I think you need the: reuseCondition="false" thing for MFA, not sure how to set that in new 4.1 installs. -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://shibboleth.net/pipermail/users/attachments/20210813/bd49721b/attachment.htm>