Issues with Passkey logins via Entra in SAML proxy mode.

Mark Cairney Mark.Cairney at ed.ac.uk
Mon Aug 3 12:16:36 UTC 2026


Hi,

We've had reports of issues logging into services protected by our 
Shibboleth IdP when using alternative authn methods like Passkeys from 
Entra in SAML proxy mode.

The error in Entra is 'Authentication method 'MultiFactor,Fido' by which 
the user authenticated with the service doesn't match requested 
authentication method 'Password, ProtectedTransport'. Contact the 
Shibboleth-Live application owner.'

Unfortunately I don't see any obvious error logs in the Shibboleth IdP 
side which suggests the issue is between the Entra IdP and the 
Shibboleth IdP (in SP mode).


I've seen some documentation e.g. 
https://shibboleth.atlassian.net/wiki/spaces/KB/pages/3503587329/Supporting+the+REFEDS+MFA+Profile+V5 
refer to the idp.authn.MFA.supportedPrincipals key but from what I can 
tell that is only applicable if you're using the MFA login flow not the 
SAML login flow used in SAML proxy mode.


Has anyone else seen this behaviour? While we're not seeing a huge 
number of issues being reported because of this (and we have a 
workaround i.e. use traditional password + MFA to login) I'm slightly 
concerned we might see more and more issues like this as these 
alternative authn methods become more popular and recommended.


Kind regards,

Mark



-- 
/****************************

Mark Cairney
ITI Enterprise Services
Information Services
University of Edinburgh

Tel: 0131 650 6565
Email: Mark.Cairney at ed.ac.uk

*******************************/

The University of Edinburgh is a charitable body, registered in Scotland, with registration number SC005336.



More information about the users mailing list