authn context comparison per relying party

Michael Grady mgrady at unicon.net
Mon Aug 24 21:13:52 UTC 2026


Is there an "authoritative/up-to-date" list of "factor" values that Duo returns? I've had trouble surfacing anything that I was convinced was current and accurate, and more concerningly, thought I saw something that suggested Duo might consider "factor" to be deprecated.

The AMR value sets Duo are returning appear to me to be useless, as everything from standard Duo Push thru to the most secure methods return the same 3 values:

  ["mfa", "pop", "user"]

and does not distinguish if Remember Me was used (if in place, you just get the value set from what was used to establish it in the first place.)

> On Aug 24, 2026, at 1:26 PM, Scott Cantor via users <users at shibboleth.net> wrote:
> 
> 
> 
>> On Aug 24, 2026, at 1:54 PM, Mak, Steven via users <users at shibboleth.net> wrote:
>> 
>> Bobby,
>> 
>> We ended up solving this by using an alternate method that Salesforce supports - a custom resolved attribute 'salesforceAMR'. This felt like a much better fit than trying to do very weird things with the ACCR.
> 
> I think I suggested that option to somebody also. It's certainly better in some sense than misusing the SAML or OpenID features the way they are.
> 
> -- Scott
> 
> -- 
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


--
Michael A. Grady
IAM Architect, Unicon, Inc.





More information about the users mailing list