Microsoft MFA (onprem or Azure)
Ramaiah, Vanna G.
ramaiah at musc.edu
Tue Mar 16 13:52:53 UTC 2021
Is there any limitations with shib proxying to another saml2 idp? The second idp we have is ADFS. It handles MFA. If authentication and MFA is handled via proxy, would that still honor REFEDS MFA requirements?
https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Peter Schober
Sent: Saturday, March 13, 2021 7:09 AM
To: users at shibboleth.net
Subject: Re: Microsoft MFA (onprem or Azure)
CAUTION: External
* Goggins, Patrick via users <users at shibboleth.net> [2021-03-12 20:58]:
> The IdP Proxy might work but there are limitations there. Otherwise
> there’s the NPS role
> (https://urldefense.com/v3/__https://docs.microsoft.com/en-us/azure/ac
> tive-directory/authentication/howto-mfa-nps-extension__;!!Ab1_Rw!RZdsM7n9wjcnfy0lVHizyMzaYEHlDabGm4Uch63sCDSKv-kUwIflmFCwYuv1vQA$ ), but those requests are via Radius which is another issue.
What's the protocol used between the "NPS Server" and "Azure MFA"?
And how does the subject (using a "VPN client") complete the "secondary authentication" triggered by the "NPS Extension"? Seemingly outside of the VPN client and RADIUS protocol -- by starting a local web browser on the client's machine pointed to some MS web server?
Well, if you own all the parts (client OS, client software, server OS in the client's data center, external services/APIs) I guess anything is possible...
-peter
--
For Consortium Member technical support, see https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!Ab1_Rw!RZdsM7n9wjcnfy0lVHizyMzaYEHlDabGm4Uch63sCDSKv-kUwIflmFCwt9je3Io$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list