Azure MFA and Shibboleth Proxy
Goggins, Patrick
gogginsp at uwgb.edu
Tue Mar 9 14:24:57 UTC 2021
The IdP Proxy will push the auth back to Azure where you can enforce MFA. Azure can be configured to release custom attributes based upon this but we found it a bit limiting and ended up doing the hybrid proxy route. Auth + Conditional MFA occurs in Azure. After the user is authorized a secondary local LDAP lookup for AD Group memberships occurs to handle the flexibility wanted for the additional assurance information wanted by some SPs.
Patrick Goggins
Senior Network/Systems Administrator
............................................................................................
Division of Information Technology
University of Wisconsin – Green Bay
From: users <users-bounces at shibboleth.net> On Behalf Of Cole Griggs
Sent: Monday, March 8, 2021 5:59 PM
To: users at shibboleth.net
Subject: FW: Azure MFA and Shibboleth Proxy
Considering the recent KB on Using SAML Proxying in the Shibboleth IdP to connect with Azure AD [1], does anyone have any guidance or have found a good source document on how to leverage Azure MFA, and brings those claims/attributes into the Shibboleth IdP, and return them to other SP’s ?
[1]https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210309/099658ae/attachment.htm>
More information about the users
mailing list