Microsoft MFA support?

Michael Grady mgrady at unicon.net
Wed Jan 8 23:34:29 UTC 2025



> On Jan 8, 2025, at 4:41 PM, Cantor, Scott via users <users at shibboleth.net> wrote:
> 
>> I'm wondering if anyone has deployed Microsoft MFA on an
>> IdP where the IdP is still doing its own password
>> authentication instead of proxying to EntraID.
> 
> My understanding was that wasn't possible. If that's untrue, I don't think I'm speaking too far afield in saying we'd be willing to support it.
> 

The Apereo CAS Server used to support this, because Microsoft used to provide an API for talking to their MFA service. But they pulled that API a few years back. I've not heard anything to make me think there is any chance they will provide that capability again.

So, bottom line, not going to be possible. You can see that as a definitive statement on this Apereo CAS Github page:

  https://github.com/apereo/cas/blob/master/docs/cas-server-documentation/mfa/Configuring-Multifactor-Authentication.md


p.s. I recall "hearing" that after Microsoft stopped supporting that API, that there was some "roundabout/Rube Goldberg" approach through a Radius server to interact with the MFA service. But I've not heard about that in the last couple of years, and never saw any hard evidence for that as a solution.


--
Michael A. Grady
IAM Architect, Unicon, Inc.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250108/2f8fca2e/attachment.htm>


More information about the users mailing list