MFA result reuse with Duo.
Scott Koranda
skoranda at gmail.com
Wed Jan 18 20:07:43 EST 2017
> I think you have your answer on this, sounds like you just
> configure the relevant SPs to request both MFA and non-MFA
> authentication classes
Can you think of any reason for a deployer with this use case
to not configure that on the DefaultRelyingParty?
(I am assuming that the MFA flow is the only enabled flow.)
Individual SPs that really do require MFA (from the IdP
perspective) can override with the single MFA principal as one
normally would...
Scott K
More information about the users
mailing list