<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Fri, Apr 4, 2014 at 4:20 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On 4/4/14, 5:06 PM, &quot;David Langenberg&quot; &lt;<a href="mailto:davel@uchicago.edu">davel@uchicago.edu</a>&gt; wrote:<br>

&gt;<br>
&gt;The SP needs to send the &quot;assurance&quot; requirement via the<br>
&gt;AuthnContextClassRef field of the AuthRequest.  You can&#39;t control on the<br>
&gt;IdP side &quot;SP X requests must do DUO&quot;.<br>
<br>
</div>Was that established? I thought you could specify a<br>
defaultAuthenticationMethod for a relying party per usual and the MCB<br>
could at least see it.<br></blockquote><div><br></div><div>I understood a recent post from Paul said no, it couldn&#39;t be done.  Paul?</div><div><br></div><div>Dave</div></div><div><br></div>-- <br>David Langenberg<div>
Identity &amp; Access Management</div><div>The University of Chicago</div>
</div></div>