<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Eric,
<div><br>
</div>
<div>
<div>
<blockquote type="cite">
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
<span style="color: rgb(31, 73, 125); ">I may be stating the obvious, but the only way you can really enforce the forcedauthn is if the SP actually checks the resultant assertion for how old it is.</span></div>
</blockquote>
<div><br>
</div>
<div>I think the SP is responsible for enforcing any check regardless, and most of the data available to it comes from the IdP. &nbsp;In both these cases, you're relying on the IdP to accurately represent what has occurred, no matter what &quot;what&quot; is, and you don't
 really have a good way of validating that beyond trusting that specific IdP.</div>
<div><br>
</div>
<div>There are ways that I could imagine the SP could &quot;whisper to itself&quot; which would be indicative, but not especially conclusive.</div>
</div>
<br>
</div>
<div>Hope I'm missing the obvious...</div>
<div>Nate.</div>
</body>
</html>