Issues with Passkey logins via Entra in SAML proxy mode.
Mark Cairney
Mark.Cairney at ed.ac.uk
Mon Aug 3 12:16:36 UTC 2026
Hi,
We've had reports of issues logging into services protected by our
Shibboleth IdP when using alternative authn methods like Passkeys from
Entra in SAML proxy mode.
The error in Entra is 'Authentication method 'MultiFactor,Fido' by which
the user authenticated with the service doesn't match requested
authentication method 'Password, ProtectedTransport'. Contact the
Shibboleth-Live application owner.'
Unfortunately I don't see any obvious error logs in the Shibboleth IdP
side which suggests the issue is between the Entra IdP and the
Shibboleth IdP (in SP mode).
I've seen some documentation e.g.
https://shibboleth.atlassian.net/wiki/spaces/KB/pages/3503587329/Supporting+the+REFEDS+MFA+Profile+V5
refer to the idp.authn.MFA.supportedPrincipals key but from what I can
tell that is only applicable if you're using the MFA login flow not the
SAML login flow used in SAML proxy mode.
Has anyone else seen this behaviour? While we're not seeing a huge
number of issues being reported because of this (and we have a
workaround i.e. use traditional password + MFA to login) I'm slightly
concerned we might see more and more issues like this as these
alternative authn methods become more popular and recommended.
Kind regards,
Mark
--
/****************************
Mark Cairney
ITI Enterprise Services
Information Services
University of Edinburgh
Tel: 0131 650 6565
Email: Mark.Cairney at ed.ac.uk
*******************************/
The University of Edinburgh is a charitable body, registered in Scotland, with registration number SC005336.
More information about the users
mailing list