Azure MFA and Shibboleth Proxy
Cantor, Scott
cantor.2 at osu.edu
Tue Mar 9 13:29:33 UTC 2021
On 3/9/21, 6:54 AM, "users on behalf of Robert Bradley" <users-bounces at shibboleth.net on behalf of robert.bradley at it.ox.ac.uk> wrote:
> It does populate AuthnContext as well, but for MFA logins, the
> AuthnContext is just "multifactor". The attributes may give you more
> information if MFA is used, but I've not created an attribute registry
> file for Azure AD attributes yet.
If that's the case I'm not sure there's that big of a problem in that direction then, I don't know what else anybody would really find interesting at scale.
> In my experience, authnContextClassRef requirements are more bother than
> they're worth outside of specific internal uses.
Exact matching works fine when they're actually implemented. The others were never well thought out and I wouldn't ever be overly critical of anybody not supporting them.
-- Scott
More information about the users
mailing list