Duke Verified: Strengthening Security for Duke’s Digital Environment
Changes will be introduced beginning this summer
June 17, 2026
Dear Students, Faculty, and Staff,
Duke University is strengthening its cybersecurity protections through Duke Verified, a university-wide initiative that brings together a series of security improvements designed to better protect the Duke community.
The recent ransomware attack of Canvas, a third-party learning management system used by Duke and thousands of academic institutions, offers another example of the urgency to strengthen security controls across all university systems.
Duke Verified’s approach to identity security is focused on ensuring that only verified, authorized individuals can access Duke systems, data, networks, and services. Some elements of Duke Verified have already been implemented, while additional capabilities will be introduced starting in Summer 2026.
Most changes will occur behind the scenes and are intended to improve security while minimizing disruption to teaching, learning, research, clinical, and administrative work.
Duke Verified efforts will focus on the following core areas:
- Stronger Identity Verification: Duke has strengthened identity verification processes by introducing services such as CLEAR, to help protect accounts and reduce identity-related fraud.
- Secure Access to Systems: Beginning in Summer 2026, some university systems and services, such as Duke@Work, DukeHub, and Canvas, will require identity verification before they can be accessed. Users may notice that certain services now direct them through a Duke verification page before connecting. This additional security step reduces opportunities for attackers to reach Duke systems.
- Safer Devices: Starting this fall, computers, phones, and tablets that connect to Duke resources will be required to have Duke-provided software installed. The software helps verify important security signals about a device, such as whether it is up to date and protected against common threats, helping Duke identify potentially compromised devices and reduce cybersecurity risk.
- Improved Protection of University Data: Duke will continue strengthening safeguards for sensitive information and improving its ability to detect, respond to, and recover from cybersecurity incidents affecting Duke systems and third-party service providers.
As these changes are rolled out, your cooperation helps support Duke’s longstanding commitment to protecting the information entrusted to us and ensures the continued availability and security of the systems that support our teaching, research, and clinical missions.
By working together, we can reduce risk, strengthen our defenses, and better protect the Duke community from evolving cyber threats. Additional information, including a timeline and frequently asked questions, is available at duke.is/DukeVerified.
Questions may be directed to security@duke.edu. Thank you for your partnership in helping maintain a secure and resilient digital environment for Duke.
Tracy Futhey,
Chief Information Officer and Vice President, Information Technology
Duke University
Nick Tripp,
Chief Information Security Officer
Duke University