<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jan 14, 2015 at 10:07 AM, Vignesh, Vanna G. <span dir="ltr">&lt;<a href="mailto:vignesh@musc.edu" target="_blank">vignesh@musc.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="blue" vlink="purple">
<div>
<p><u></u><span>a)<span style="font:7.0pt &quot;Times New Roman&quot;">     
</span></span><u></u>Can MCB alone do the multi factor authentication without installing Duo? If yes, how? Apart from username-password auth, what are the other auth mechanisms it support?</p></div></div></blockquote><div><br></div><div>Sure, but unless you&#39;re using Duo or Toopher as your MFA solution you&#39;ll have to write your own MCB module to support your alternate MFA technology.</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div lang="EN-US" link="blue" vlink="purple"><div><p><u></u><u></u></p>
<p><u></u><span>b)<span style="font:7.0pt &quot;Times New Roman&quot;">     
</span></span><u></u>Where should I code to trigger the second level authentication (phone authentication from Microsoft)? Can someone give examples please?</p></div></div></blockquote><div>With the MCB that&#39;s all done in configuration.  It&#39;s based on the authnContextClass passed in the AuthRequest combined with the allowed authnContextClasses listed in the IDMS attribute coming from the attribute resolver.</div><div><br></div><div>Dave</div><div><br></div></div>-- <br><div class="gmail_signature">David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div></div>
</div></div>