The following page offers advice for planning and handling outages to the Duo Security service.
Duo offers a specific status page, https://status.duo.com/ with outage information, and is a good place to start.
A few solutions were offered to support a fail-open integration, to allow AuthN to continue in a weakened state:
When the IdP is authenticating in bypass mode, what should be sent to SPs indicating that the AuthN context is different?
If Duo is part of the assurance, the IdP should not assert the assurance level.