> So could I simply call getInitialAuthenticationResult() on the > authentication context and if a result is returned I know this > is not SSO? If it did SSO, it wouldn't have done initial-authn since the user was already identified. So yes, I think so. > Sorry for the retching. I'm the one who made the mistake and added that to buy time. -- Scott