<div dir="ltr"><div>We have several Shibboleth IDP customers with Duo MFA, and since mid-day last Tuesday 2029-09-08 two of them are reporting SSO failures when the end user has an existing Shibboleth SSO session, and a login to a new SP with forceauthn is sent. </div><div>We are seeing a authnfailure sent to the SP.</div><div><br></div><div>2026-09-08 14:18:24 (ET)</div><div><saml2p:Status><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester"><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/></saml2p:StatusCode><saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage></saml2p:Status></div><div><br></div><div>Does anyone know if there were any default changes published just before then? I am still working with the two IDPs that are experiencing this issue to determine if anything was installed on their IDP systems which correlate to this, and I have opened a ticket with Duo as well.</div><div><br></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr">Brian Rose<br>Point and Click Solutions, Inc.<br><div dir="ltr"><div dir="ltr">Chief Information Security Officer</div></div>916-800-2338</div></div></div></div></div></div>