Azure MFA and Shibboleth Proxy

Goggins, Patrick gogginsp at uwgb.edu
Tue Mar 9 14:24:57 UTC 2021


The IdP Proxy will push the auth back to Azure where you can enforce MFA. Azure can be configured to release custom attributes based upon this but we found it a bit limiting and ended up doing the hybrid proxy route. Auth + Conditional MFA  occurs in Azure. After the user is authorized a secondary local LDAP lookup for AD Group memberships occurs to handle the flexibility wanted for the additional assurance information wanted by some SPs.


Patrick Goggins
Senior Network/Systems Administrator
............................................................................................
Division of Information Technology
University of Wisconsin – Green Bay



From: users <users-bounces at shibboleth.net> On Behalf Of Cole Griggs
Sent: Monday, March 8, 2021 5:59 PM
To: users at shibboleth.net
Subject: FW: Azure MFA and Shibboleth Proxy

Considering the recent KB on Using SAML Proxying in the Shibboleth IdP to connect with Azure AD [1], does anyone have any guidance or have found a good source document on how to leverage Azure MFA, and brings those claims/attributes into the Shibboleth IdP, and return them to other SP’s ?



[1]https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210309/099658ae/attachment.htm>


More information about the users mailing list