SP Requiring/Requesting MFA (was Re: Customizing Second Factor Configuration in mfa-authn-config.xml)
Cantor, Scott
cantor.2 at osu.edu
Mon Apr 26 15:32:41 UTC 2021
On 4/26/21, 10:52 AM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:
> I found that one of our service providers works with an IDP that doesn't support MFA - yet when I enable
> MFA support, logins to the SP execute the MFA flow. If the SP required it shouldn't it have failed before?
I don't undertand the question. I don't know anything about your MFA configuration either, but a configuration that bases a decision on whether the request requires a custom Principal that is associated with the second factor won't apply that factor unless the IdP sees something in the AuthnRequest or has a defaultAuthenticationMethods property active for that SP.
Whether the MFA flow itself always *runs* is a very different sort of question and has much more variability.
-- Scott
More information about the users
mailing list