> includes "This login handler does not support the SAML 2 forced re- > authentication or passive authentication feature." > > Do you happen to recall if "does not support" meant that the IdP would send > the SP a SAML error if the SP included isPassive in the authnRequest? I believe so, yes. -- Scott