SP Requiring/Requesting MFA (was Re: Customizing Second Factor Configuration in mfa-authn-config.xml)

Cantor, Scott cantor.2 at osu.edu
Mon Apr 26 15:32:41 UTC 2021


On 4/26/21, 10:52 AM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:

>    I found that one of our service providers works with an IDP that doesn't support MFA - yet when I enable
> MFA support, logins to the SP execute the MFA flow. If the SP required it shouldn't it have failed before?

I don't undertand the question. I don't know anything about your MFA configuration either, but a configuration that bases a decision on whether the request requires a custom Principal that is associated with the second factor won't apply that factor unless the IdP sees something in the AuthnRequest or has a defaultAuthenticationMethods property active for that SP.

Whether the MFA flow itself always *runs* is a very different sort of question and has much more variability.

-- Scott




More information about the users mailing list