Azure MFA and Shibboleth Proxy

Cantor, Scott cantor.2 at osu.edu
Tue Mar 9 13:29:33 UTC 2021


On 3/9/21, 6:54 AM, "users on behalf of Robert Bradley" <users-bounces at shibboleth.net on behalf of robert.bradley at it.ox.ac.uk> wrote:

>    It does populate AuthnContext as well, but for MFA logins, the 
>    AuthnContext is just "multifactor".  The attributes may give you more 
>    information if MFA is used, but I've not created an attribute registry 
 >   file for Azure AD attributes yet.

If that's the case I'm not sure there's that big of a problem in that direction then, I don't know what else anybody would really find interesting at scale.

>    In my experience, authnContextClassRef requirements are more bother than 
>    they're worth outside of specific internal uses.

Exact matching works fine when they're actually implemented. The others were never well thought out and I wouldn't ever be overly critical of anybody not supporting them.

-- Scott




More information about the users mailing list