<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Georgia;
        panose-1:2 4 5 2 5 4 5 2 3 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>Hello:<o:p></o:p></p><p class=MsoNormal>I am researching using multifactor authentication using the MFA Login handler in Shibboleth, and I&#8217;m trying to understand the workflow for federated identities that use services within our organization.&nbsp; <o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>If a user authenticates within another organization and they have an active Shibboleth session and try to visit a service provider within our organization, is it implied that we continue to trust our federated partners but are adding an extra level of security in authenticating our own users through MFA on our local IdP?&nbsp; It seems that even though we are requiring a certain level of authentication within our own accounts, that we may or may not receive the same level of security from our partners.&nbsp; Is this correct?<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Thanks in advance for any clarification on this topic.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:9.0pt;font-family:"Georgia","serif"'>Rob Castellow<o:p></o:p></span></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:9.0pt;font-family:"Georgia","serif"'>Systems Engineer<o:p></o:p></span></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:9.0pt;font-family:"Georgia","serif"'>IAS, OCIO<o:p></o:p></span></p><p class=MsoNormal style='margin-left:.25in'><i><span style='font-size:9.0pt;font-family:"Georgia","serif"'>Medical University of South Carolina<o:p></o:p></span></i></p><p class=MsoNormal><o:p>&nbsp;</o:p></p></div></body></html>