mitigating the effects of forceAuthn terrorism

Scott Cantor scott at restingparrotsoftware.com
Thu Apr 9 14:57:26 UTC 2026


My sense is there might be a change to the MFA flow that would provide a bit less rigidity to the behavior, but it would take some testing, and it would be very sensitive to the particulars of somebody's MFA flow rules. I imagine it would lead to holes in the ForceAuthn semantic in certain cases as well.

I would consider it at some point, but a RFE would have to be filed to get into it.

-- Scott



More information about the users mailing list