> We use ExternalAuth. > In IDP V2 we set the Request-Attribute > *ExternalAuthentication.AUTHN_METHOD_PARAM* to adapt > AuthnContextClass to the result of the external flow. That's not what he was asking about, that's the "reverse", a deprecated way to express the SP's requirements, which are not possible to carry in a single parameter. -- Scott