Skip to content

Incident detail

All Deployments: Duo Enrollment URL Session Expired Errors

Resolved incidentMinor1 affected service

Timeline window

to

Outage alerts

Get alerted the next time Cisco Duo breaks

Free email alerts for up to 5 providers — no card, live in about a minute. Paid plans add Slack, Discord, and webhook delivery across your whole stack, plus higher API quotas.

Timeline

Incident updates

Updates are normalized from the official source chronology so timeline changes remain easy to scan.

  1. Identified

    We have Identified the cause of enrollment failures that display the error message "Your session has expired. Please try again." and are working to correct the issue as soon as possible.

    As a workaround:

    -If using enrollment email links, update the enrollment experience settings (https://duo.com/docs/administration-settings#enrollment) to show New Universal Prompt.

    -If enrolling using in-line self enrollment with an existing application (https://duo.com/docs/enrolling-users#inline-self-enrollment), update that application to use the Universal Prompt (https://duo.com/docs/universal-prompt-update-guide).

    -You can also enroll users manually from the Duo Admin Panel (https://duo.com/docs/administration-devices#adding-a-2fa-device-to-a-user) or issue an enrollment code for self-enrollment (https://duo.com/docs/enrolling-users#generate-enrollment-codes-for-existing-users).

    Please check back here or subscribe to updates for any changes.

  2. Monitoring

    We have implemented a fix for the enrollment failures that caused the error message "Your session has expired. Please try again." and are monitoring the results closely.

  3. Resolved

    The issue causing enrollment failures that display the error message "Your session has expired. Please try again." has been resolved.

  4. Resolved

    # Enrollment Timeout Outage

    Incident Report – 02/04/2026

    ## Summary

    A recent software update Duo made related to certificate security improvements inadvertently changed the order of operations for user sessions in our legacy enrollment experience. This resulted in user sessions not being properly initialized, prompting the system to mistakenly identify these sessions as expired. Affected users were unable to complete enrollment and saw the message: “Your session has expired. Please try again.” The issue only affected enrollment flows using the legacy Traditional Prompt. Customers were able to successfully enroll by switching to the Universal Prompt enrollment experience as a workaround.

    Duo identified and corrected the issue by ensuring sessions are fully initialized before they are used. The fix was deployed on 2026-02-04, and enrollment is now functioning normally.

    Duo has implemented additional safeguards to prevent similar session handling issues in future updates.

    ## Timeline of Events

    Date/Time (in EST)

    02/04/2026 03:57AM  - Duo receives reports that customers are unable to complete enrollments

    02/04/2026 09:00 AM - Authentication team starts investigating

    02/04/2026 10:42 AM - Authentication team identifies root cause

    02/04/2026 3:40 PM - The fix begins rolling out to customers

    02/04/2026 7:26 PM - The fix finishes rolling out to customers

    02/04/2026 7:26 PM - Duo confirms that enrollments are working as intended