> We use AuthenticationContext in SAML to handle that, and the IdP already > enforces that. (To clarify, while that normally does involve the SP, you can default in RequestedAuthnContext behavior in most cases via a relying-party setting that imposes a predefined rule to apply to the request if the SP doesn't ask for anything.) -- Scott