Enabling MFA on Shibboleth IDP 4.01

Cantor, Scott cantor.2 at osu.edu
Mon Feb 21 13:09:55 UTC 2022


>    Hi, Our Shibboleth IdP instance 4.0.1 has been configured to use Azure AD for authentication. The Azure AD
> itself is configured for multifactor authentication (MFA). I would like to know if IdP MFA is independent of
> Azure AD MFA? If yes, is it possible to enable MFA on our IdP instance? Can someone please share the steps
> involved in enabling MFA.

The steps are:

- understand the IdP, and your needs, in detail
- configure it to meet those needs

Every other supposed recipe just makes very specific assumptions about those needs.

The IdP includes a couple of built-in or plugin-supplied options for MFA but only the Duo support for people buying that service is a fully practical solution at this point, other than the External/RemoteUser and SAML proxy support allowing authentication to be punted to some other system entirely.

The IdP also includes a login flow termed "MFA" but which is really just a scriptable orchestration layer for combining login methods in a programmable way to meet essentially an endless possible set of requirements that all differ from site to site.

-- Scott




More information about the users mailing list