Logic for mfa-authn-config.xml

Tom Poage tfpoage at ucdavis.edu
Fri Jan 12 09:43:20 EST 2018


> On Jan 11, 2018, at 6:46 PM, Paul B. Henson <henson at cpp.edu> wrote:
...
> In our case, all faculty and staff will have MFA available, but possibly not students depending on cost and certainly not applicants, who also have accounts and need to access some of the same services as everybody else.

Our twist on opportunistic MFA (in the ongoing evolution of managing risk) is currently user opt-in. Management policy and enforcement then deals with (the relatively few) users requiring elevated privileges. Yes, it's a blunt hammer, but closes most of the gap, and does that part one step better by fully protecting the user. One hundred percent comes later. :-)

Tom.


More information about the users mailing list