SP require MFA for existing session
Bobby Lawrence
robertl at jlab.org
Fri Apr 24 12:26:52 UTC 2026
I haven't found a way to do this yet so I figured I ask...
I'm running SP v3.4.1.4 on IIS. Before you say it, I know...the current version is 3.5.2.x and I need to upgrade but my SPs are not exposed outside our firewall and I didn't see anything in the release notes which seemed like it was super urgent or might be the cause of my issue.
I want to require MFA for a particular virtual directory, but when a user already has a session on my SP, it seems like the SP software just lets them right in. I know I can enforce AccessControl policies on that path, but I'd rather send the user back to the IdP and require them to do some kind of MFA.
I've tried setting the authnContextClassRef (along with forceAuthn) on the request mapper path element, but it doesn't seem to do anything. The user isn't redirected back to the IdP to step up their authentication.
Is what I'm doing even possible?
Thanks in advance...
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260424/32066024/attachment.htm>
More information about the users
mailing list