Okta Post-Transition Notes

Continue using Duo for SSH and RDP connections

SSH and RDP are remaining on Duo after February 25, 2026 until protected systems can be updated. The transition to Okta for SSH and RDP connections has two dependencies:

  • All users who could potentially sign into a resource using these protocols have to be in Okta in order to fulfill MFA prompts. The only time this is guaranteed is after February 25, 2026.
  • The Duo and Okta solutions for MFA on RDP cannot co-exist. Maintainers of protected systems must complete a maintenance task to swap Duo software for Okta software as well as coordinating that change with users of the system. Extending Duo protection allows for time to schedule maintenance and get users transitioned.

More information about transitioning to direct Okta SSO

Shibboleth will eventually be replaced by Okta over the course of the 2026 calendar year. Transition plans for applications to migrate off Shibboleth to Okta will be shared in 2026 and individual service owners will be contacted directly by the Wolverine Identity Program to plan and schedule their service’s move to Okta. Okta provides all similar integration protocols, such as SAML and OIDC.