If your application checks for mfa-enrolled to be returned by CAS or LDAP in the uhReleasedGrouping attribute, you should now change it to check for this value instead:
hawaii.edu:store:uhims:general:mfa-enabled
This new value is more accurate for surmising that a person went through Duo MFA. That's because it won't include people who are in Duo bypass mode. Note however that departmental accounts are currently not supported for this value (it wasn't supported under the old value either).
You can go ahead and make the change now. The new value has been deployed as of 9:00 AM, Wednesday, September 19, 2019. The old value of mfa-enrolled will be removed on January 15, 2019.
Notice how the new value is longer and embedded in colon-delimited folders. This is the format we will use for all of our curated groupings.