authn context comparison per relying party

Mak, Steven makst at upenn.edu
Tue Aug 25 12:17:11 UTC 2026


I used the duo admin api guide (https://duo.com/docs/adminapi#authentication-logs). They list all of the currently possible MFA types in the  "factors" key.

- Steve

From: users <users-bounces at shibboleth.net> on behalf of Michael Grady via users <users at shibboleth.net>
Date: Monday, August 24, 2026 at 5:14 PM
To: Shib Users <users at shibboleth.net>
Cc: Michael Grady <mgrady at unicon.net>
Subject: Re: authn context comparison per relying party

Is there an "authoritative/up-to-date" list of "factor" values that Duo returns? I've had trouble surfacing anything that I was convinced was current and accurate, and more concerningly, thought I saw something that suggested Duo might consider "factor" to be deprecated.

The AMR value sets Duo are returning appear to me to be useless, as everything from standard Duo Push thru to the most secure methods return the same 3 values:

  ["mfa", "pop", "user"]

and does not distinguish if Remember Me was used (if in place, you just get the value set from what was used to establish it in the first place.)

> On Aug 24, 2026, at 1:26 PM, Scott Cantor via users <users at shibboleth.net> wrote:
>
>
>
>> On Aug 24, 2026, at 1:54 PM, Mak, Steven via users <users at shibboleth.net> wrote:
>>
>> Bobby,
>>
>> We ended up solving this by using an alternate method that Salesforce supports - a custom resolved attribute 'salesforceAMR'. This felt like a much better fit than trying to do very weird things with the ACCR.
>
> I think I suggested that option to somebody also. It's certainly better in some sense than misusing the SAML or OpenID features the way they are.
>
> -- Scott
>
> --
> For Consortium Member technical support, see https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!IBzWLUs!RoJN5TqJgxIqBjxs0ZTf5glsku1fHX05K56av_eI8jtYfx61kOu_Kf6ytqqRoII_uddkzKyXCVx8YY3i$
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


--
Michael A. Grady
IAM Architect, Unicon, Inc.



--
For Consortium Member technical support, see https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!IBzWLUs!RoJN5TqJgxIqBjxs0ZTf5glsku1fHX05K56av_eI8jtYfx61kOu_Kf6ytqqRoII_uddkzKyXCVx8YY3i$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260825/af73d2a8/attachment.htm>


More information about the users mailing list