Version 6.0.0
High priority
General Availability of Offline Access for Passwordless OS Logon, plus 12 more changes.
This release has 2 changes that need attention before upgrading, 2 security changes, 2 fixes and 7 new features and improvements.
Action required
- Removes support for TLS 1.1 and earlier. Connections to Duo's cloud service now require TLS 1.2 or later.
- The installer now enforces OS version compliance, permitting installation only on Windows 10 and later or Windows Server 2016 and later. This matches the stated supported operating systems.
Security
- Migrates cryptographic operations from legacy CAPI to CNG and from DPAPI to DPAPI NG to support FIPS compliance requirements.
- "Remember Me" is now disabled during cross-session UAC elevation and password reset flows.
Fixes
- Fixes and enhancements for password reset during Windows logon.
- Corrects an issue where trusted sessions did not work correctly when multiple users had active sessions on the same machine.
- Additional security improvements and bug fixes.
New & improved
- General Availability of Offline Access for Passwordless OS Logon.
- Adds the Duo WinLogon Support Tool, a graphical diagnostic application for collecting logs, viewing log files, checking Duo connectivity, and validating time synchronization.
- Updates the PowerShell support script (Winlogon-Diag.ps1) to remove the dependency on Internet Explorer, update the connectivity check to use Invoke-RestMethod, add GPO registry key collection, RDP and NLA status reporting…
- Adds support for GoTrustID security keys for offline authentication.
- Adds the EnableSSPRFix registry value to permit Microsoft Entra ID Self-Service Password Reset (SSPR).
- The executable installer now displays the VC++ Redistributable installer if not already present, allowing the user to control any required reboot before Duo setup continues.
- …and 1 more in the release notes.
Original release notes
- General Availability of Offline Access for Passwordless OS Logon.
- Adds the Duo WinLogon Support Tool, a graphical diagnostic application for collecting logs, viewing log files, checking Duo connectivity, and validating time synchronization.
- Updates the PowerShell support script (Winlogon-Diag.ps1) to remove the dependency on Internet Explorer, update the connectivity check to use Invoke-RestMethod, add GPO registry key collection, RDP and NLA status reporting, UAC and policy analysis output, and remove legacy Windows 7/Vista code paths.
- Adds support for GoTrustID security keys for offline authentication.
- Adds the EnableSSPRFix registry value to permit Microsoft Entra ID Self-Service Password Reset (SSPR).
- Removes support for TLS 1.1 and earlier. Connections to Duo's cloud service now require TLS 1.2 or later.
- Migrates cryptographic operations from legacy CAPI to CNG and from DPAPI to DPAPI NG to support FIPS compliance requirements.
- "Remember Me" is now disabled during cross-session UAC elevation and password reset flows.
- Fixes and enhancements for password reset during Windows logon.
- The executable installer now displays the VC++ Redistributable installer if not already present, allowing the user to control any required reboot before Duo setup continues.
- The installer now enforces OS version compliance, permitting installation only on Windows 10 and later or Windows Server 2016 and later. This matches the stated supported operating systems.
- Corrects an issue where trusted sessions did not work correctly when multiple users had active sessions on the same machine.
- Improvements to Bluetooth adapter detection and BLE connection stability.
- Additional security improvements and bug fixes.