Customizing Second Factor Configuration in mfa-authn-config.xml

Cantor, Scott cantor.2 at osu.edu
Thu Apr 22 20:22:41 UTC 2021


> I noticed that this code allows MFA from the NIH Security Compliance tool
> (without any further configuration on our end in relying-party) - I assume that's
> because the tool requests (requires?) MFA?

It does, yes.

> Can these MFA requests sent by the SP be optional or is an MFA request always
> a mandatory requirement?

What is requested is mandatory. Whether that's MFA alone or not depends on what's requested.

-- Scott



More information about the users mailing list