Using IgnoredContexts to work around a fussy SP

Cantor, Scott cantor.2 at osu.edu
Fri Feb 2 13:08:29 UTC 2024


> What I'd like to know is, is there any risks by doing this?

You're literally configuring your IdP to lie. That's a serious bridge to cross.

> And is there a way to do this just for the single SP that has this problem?

Via MFA scripting it's certainly possible to break the IdP in a more limited fashion, but I don't see the point. If you're willing to lie to one, not much point worrying about any others doing the same thing.

Anything asking for Password is simply broken and doesn't have any idea what its doing or why. But my view is that it doesn't justify lying to them, I simply explain the situation and they do what they choose to do.

Notably, if you sent that same context to Entra, and it did passwordless, then Entra is also seriously broken.

-- Scott




More information about the users mailing list