Microsoft MFA (onprem or Azure)

Goggins, Patrick gogginsp at uwgb.edu
Tue Mar 16 14:17:55 UTC 2021


The biggest limit is it appears as a single entityID to the other IdP. So if you are proxying the request back to Azure AD, it's a single enterprise app on the Azure side of things this results in whatever your O365 authentication policies are will be enforced for all entityID's tied into your Shibboleth deployment. The result is if you were to use this for InCommon/EduGain/ect and had MFA for all employees into O365, everything on the federation would now require MFA for all employees.

REFEDS will be unique per environment on how you confirm it. For us, we needed to do a hybrid deployment with local LDAP lookups to handle the MFA verification as Azure is a bit limited on the claims release vs Shibboleth scripted queries.

-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Ramaiah, Vanna G.
Sent: Tuesday, March 16, 2021 8:53 AM
To: Shib Users <users at shibboleth.net>
Subject: RE: Microsoft MFA (onprem or Azure)

Is there any limitations with shib proxying to another saml2 idp? The second idp we have is ADFS. It handles MFA. If authentication and MFA is handled via proxy,  would that still honor REFEDS MFA requirements?
https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP



-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Peter Schober
Sent: Saturday, March 13, 2021 7:09 AM
To: users at shibboleth.net
Subject: Re: Microsoft MFA (onprem or Azure)

CAUTION: External

* Goggins, Patrick via users <users at shibboleth.net> [2021-03-12 20:58]:
> The IdP Proxy might work but there are limitations there. Otherwise 
> there’s the NPS role 
> (https://urldefense.com/v3/__https://docs.microsoft.com/en-us/azure/ac
> tive-directory/authentication/howto-mfa-nps-extension__;!!Ab1_Rw!RZdsM7n9wjcnfy0lVHizyMzaYEHlDabGm4Uch63sCDSKv-kUwIflmFCwYuv1vQA$ ), but those requests are via Radius which is another issue.

What's the protocol used between the "NPS Server" and "Azure MFA"?
And how does the subject (using a "VPN client") complete the "secondary authentication" triggered by the "NPS Extension"? Seemingly outside of the VPN client and RADIUS protocol -- by starting a local web browser on the client's machine pointed to some MS web server?

Well, if you own all the parts (client OS, client software, server OS in the client's data center, external services/APIs) I guess anything is possible...

-peter
--
For Consortium Member technical support, see https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!Ab1_Rw!RZdsM7n9wjcnfy0lVHizyMzaYEHlDabGm4Uch63sCDSKv-kUwIflmFCwt9je3Io$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list