Skip to main content

Project Status: Complete

On January 27, 2026, some Two-Step Verification (Duo) settings were modified to enhance security and increase the support feature set of the service. 

Who Was Affected?

  • All users of Two-Step Verification (Duo) were affected.
  • This included users who were required to use Two-Step Verification for the Entra ID tenant on January 26, 2026.

What Changed? 

Setting Previous StateWhat ChangedBenefitsUser Experience Change 
Duo Mobile App – Instant RestoreInstant Restore was not enabledInstant Restore enabled for recovery of Duo-protected accounts; Instant Restore details Reduces support burden and allows users to self-recover their accounts when they change phonesNone 
Phone Callback KeysUsers could press any key to authenticate

Users press different keys to authenticate or report fraud:

* - to verify
3 - to report fraud

Allows users to report suspicious or fraudulent activity (e.g., they did not initiate a request); reduces risk of accidentally pressing a key to authenticate a malicious actionFor the phone callback option, users must press “*” (asterisk) to authenticate
SMS PasscodesSMS codes did not expireCodes expire after 1 minutePrevents codes from being saved up and/or phished and used laterUsers need to use their codes relatively promptly once received
SMS PasscodesSMS message had no information about the sensitivity of the SMS passcodeMessaging added: “Penn support will never ask for your code”Warns users that the code should not be shared and the University will never ask for the codeNone 
Block Duo Push AttemptsAny number of Duo Push attempts could occur in rapid successionBlock push attempts that occur within 15 seconds of an unanswered attempt; blocked attempts will be reported in the Authentication Log as “frequent attempts”Prevents phishing activity and authentication fraud; prevents an excessive number of pushes being sent to a user all at onceUsers must acknowledge a push as it occurs before requesting another push

Help & Resources