[Ext] Re: Forcing Duo by Service Provider
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 31 18:19:23 EDT 2017
On 3/31/17, 6:14 PM, "users on behalf of Andrew Morgan" <users-bounces at shibboleth.net on behalf of morgan at orst.edu> wrote:
> Agreed! A simple solution is to use MFA all the time for people that have
> enrolled in MFA (and require certain populations to enroll).
That "have enrolled" bit is where you're going to magnify the pain here. Especially when Duo just enrolls you in real time anyway.
> I'm investigating all of our possibilities to inform our policy-making
> process. We want to know what is possible, and how difficult it is, for
> all of the scenarios we have dreamed up. :)
User-specific rules are going to take the IdP complexity level up an order of magnitude, so if you're really exploring the options, I would advise against that in the strongest terms.
I can also personally vouch for that. We have only service-specific policy at this point at OSU-East and the IdP work has been minimal. The IdP is simply already set up to do service-based rules, whereas user-based is just not ever going to be clean because of the fundamental problem: you don't know who the user is until you know who the user is.
-- Scott
More information about the users
mailing list