IDPv3.3 and programmatically selecting MFA based on attribute
Cantor, Scott
cantor.2 at osu.edu
Thu Mar 23 11:22:11 EDT 2017
> When I login to a non-Duo SP, then login to a Duo SP, I get prompted again
> for login instead of just the secondFactor. Here's what I'm seeing in the logs.
You're using at least one feature that can't really be used with the MFA flow, the filtering flows by attribute thing. Don't use that (it's deprecated anyway). I would guess that's ultimately the cause of your problem, but I won't spend any time on it until that's gone and the picture is clearer.
If you want to apply logic based on an attribute, that needs to be inside your MFA transition rules and scripts.
-- Scott
More information about the users
mailing list