Azure MFA with Shibboleth
Greg Haverkamp
gahaverkamp at lbl.gov
Thu Jun 28 21:09:11 EDT 2018
On Thu, Jun 28, 2018 at 1:33 PM Sean Flannery <sean.flannery at jwt.com> wrote:
>
> We could just roll out #2 (Azure as IDP) to all the apps and achieve MFA
> coverage but Azure as IDP is a lot more restrictive than shibboleth IDP.
> For various reasons we greatly prefer shibboleth IDP.
>
> But most our users are doing MFA in Azure for their webmail and they use
> the MS Authenticator app on their watch or phone and like it.
>
> So we would prefer to design something where we can use shibboleth as IDP
> (to keep IT happy) but Azure is --some how-- MFA provider (to keep users
> happy). That is essentially the ask: shib IDP with azure MFA.
>
> As I think about it, I think we would less want to use ADFS which I think
> would be heading in the opposite direction (Azure login deferring to
> shibboleth IDP) and more, if possible, setup a shibboleth IDP to use Azure
> as an external auth source where azure also provides MFA?
>
Are both ADFS and the Shibboleth IdP using Azure AD as the directory? One
solution would be to authenticate Shibboleth with ADFS, with the Shibboleth
IdP being an SP.
But you’d prefer to use the Shibboleth IdP as the primary IdP, there seem
to be two options in the documtation. There appears to be an on-prem
option; I don’t know if that’s doable for you, but it has RADIUS and LDAP
interfaces. The latter could likely be used with a few modifications to
the existing Shibboleth LDAP authentication modules. (I thought I had seen
where someone had done RADIUS at some point; maybe that was JAAS?).
Alternatively, it looks like they have an API:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-sdk
Greg
> Hopefully this detail helps some and that I'm getting enough of the
> terminology right to explain.
>
> Appreciate the time. Any suggestions would be appreciate.
>
> Sean
>
> ------------------------------
> *From:* users <users-bounces at shibboleth.net> on behalf of Peter Schober <
> peter.schober at univie.ac.at>
> *Sent:* Thursday, June 28, 2018 2:01:45 PM
> *To:* users at shibboleth.net
> *Subject:* Re: Azure MFA with Shibboleth
>
> * Sean Flannery <sean.flannery at jwt.com> [2018-06-28 19:45]:
> > This question is a bit broad but, does anyone have any experience
> > using Shibboleth IDP with Azure ADFS and Azure MFA?
>
> Could you be more specific what exactly the connection between those
> terms should be?
>
> -peter
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180628/347af2b9/attachment.html>
More information about the users
mailing list