Skip navigation

Duo Legacy AD Protection - Release Notes

Last updated:

Seamlessly add Duo MFA to on-premises and legacy applications authenticating through Active Directory (Kerberos and NTLM).

Product Downloads

Download the current release from the Checksums and Downloads page.

Version 1.0.1 - August 25, 2026

  • Corrects an issue where SuppressDuplicatePushDuration could allow duplicate pushes during Remote Desktop logons when set to the five-second default.

Version 1.0.0 - August 25, 2026

  • General availability release of Duo Legacy AD Protection.
    • The installer package has been renamed from duo-subauthfilter to duo-legacy-ad-protection.
  • Authentication calls to Duo now pass the IP address of the target host for Interactive logon types for use with Authorized Networks policy. For Network logon types, the passed IP address is 0.0.0.0.
  • Changed SuppressDuplicatePushDuration default from 30 seconds to 5 seconds for improved security.
  • Added EnableRequestEventLogging registry setting to write authentication request outcomes to the Windows Event Log (disabled by default).
  • Logging updates:
    • Log entries now include the logon type (Interactive or Network) of the subauthentication request.
    • Renamed log result Bypass_Allowed_User to Bypass_Local_User.
    • Removed log result Bypass_Allowed_Host.
  • Removed BypassStandaloneHosts setting.
  • Added LegacyAD-Diag.ps1 support script for collecting diagnostic information.

Version 0.3.0 - May 14, 2026

  • Public beta release of Duo Legacy AD Protection.