> https://refeds.org/profile/mfa is an AuthnContextClassRef inserted into SAML Req/Resp. Is there any entity category
> that ensures a particular IDP supports this Authn Context?

That doesn't have any value. If you don't *need* it, don't ask for it. If you do need it, then you ask, and when you get an error back, you know they didn't support it (which by definition implies you can't let them login anyway).

