why/how is IdP login page displayed for unknown Service

IAM David Bantz dabantz at alaska.edu
Thu Jul 15 19:35:43 UTC 2021


Our IT helpdesk reports failed attempts to login to a service (“DemandTools
by Validity”) and provided screen shots of what appears to be our IdP
(Shibb v 4.0) login page embedded in a vendor web page. The service is
neither federated nor locally (1:1) configured. It seems to piggy-back or
otherwise co-opt a different Salesforce service that relies on our IdP.
Further confounding me, DemandTools documentation states that SSO is done
via OAuth only (
https://community.validity.com/customers/s/article/DemandTools-Login-Options).
How is a non-federated service we’ve never heard of able to get a response
from the IdP embedded on their web page, and allegedly allow (OAuth) logins
“sometimes” as long as Duo MFA is not invoked?

David St. Pierre Bantz
U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210715/2b932726/attachment.htm>


More information about the users mailing list