Duo Security incident
All Deployments: Duo Enrollment URL Session Expired Errors
Affected components
Update timeline
- identified Feb 04, 2026, 06:55 PM UTC
We have Identified the cause of enrollment failures that display the error message "Your session has expired. Please try again." and are working to correct the issue as soon as possible. As a workaround: -If using enrollment email links, update the enrollment experience settings (https://duo.com/docs/administration-settings#enrollment) to show New Universal Prompt. -If enrolling using in-line self enrollment with an existing application (https://duo.com/docs/enrolling-users#inline-self-enrollment), update that application to use the Universal Prompt (https://duo.com/docs/universal-prompt-update-guide). -You can also enroll users manually from the Duo Admin Panel (https://duo.com/docs/administration-devices#adding-a-2fa-device-to-a-user) or issue an enrollment code for self-enrollment (https://duo.com/docs/enrolling-users#generate-enrollment-codes-for-existing-users). Please check back here or subscribe to updates for any changes.
- monitoring Feb 05, 2026, 12:56 AM UTC
We have implemented a fix for the enrollment failures that caused the error message "Your session has expired. Please try again." and are monitoring the results closely.
- resolved Feb 05, 2026, 01:11 AM UTC
The issue causing enrollment failures that display the error message "Your session has expired. Please try again." has been resolved.
- postmortem Feb 10, 2026, 09:18 PM UTC
# **Enrollment Timeout Outage** Incident Report – 02/04/2026 ## Summary A recent software update Duo made related to certificate security improvements inadvertently changed the order of operations for user sessions in our legacy enrollment experience. This resulted in user sessions not being properly initialized, prompting the system to mistakenly identify these sessions as expired. Affected users were unable to complete enrollment and saw the message: “Your session has expired. Please try again.” The issue only affected enrollment flows using the legacy Traditional Prompt. Customers were able to successfully enroll by switching to the Universal Prompt enrollment experience as a workaround. Duo identified and corrected the issue by ensuring sessions are fully initialized before they are used. The fix was deployed on 2026-02-04, and enrollment is now functioning normally. Duo has implemented additional safeguards to prevent similar session handling issues in future updates. ## Timeline of Events **Date/Time \(in EST\)** 02/04/2026 03:57AM - Duo receives reports that customers are unable to complete enrollments 02/04/2026 09:00 AM - Authentication team starts investigating 02/04/2026 10:42 AM - Authentication team identifies root cause 02/04/2026 3:40 PM - The fix begins rolling out to customers 02/04/2026 7:26 PM - The fix finishes rolling out to customers 02/04/2026 7:26 PM - Duo confirms that enrollments are working as intended
Looking to track Duo Security downtime and outages?
Pingoru polls Duo Security's status page every 5 minutes and alerts you the moment it reports an issue — before your customers do.
- Real-time alerts when Duo Security reports an incident
- Email, Slack, Discord, Microsoft Teams, and webhook notifications
- Track Duo Security alongside 5,000+ providers in one dashboard
- Component-level filtering
- Notification groups + maintenance calendar
5 free monitors · No credit card required