<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Eric,
<div><br>
</div>
<div>
<div>
<blockquote type="cite">
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
<span style="color: rgb(31, 73, 125); ">I may be stating the obvious, but the only way you can really enforce the forcedauthn is if the SP actually checks the resultant assertion for how old it is.</span></div>
</blockquote>
<div><br>
</div>
<div>I think the SP is responsible for enforcing any check regardless, and most of the data available to it comes from the IdP. In both these cases, you're relying on the IdP to accurately represent what has occurred, no matter what "what" is, and you don't
really have a good way of validating that beyond trusting that specific IdP.</div>
<div><br>
</div>
<div>There are ways that I could imagine the SP could "whisper to itself" which would be indicative, but not especially conclusive.</div>
</div>
<br>
</div>
<div>Hope I'm missing the obvious...</div>
<div>Nate.</div>
</body>
</html>