<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Can I borrow that phrase? People of the ADFS sounds like one of those prehistoric tribes, &quot;people of the Mammoth&quot;.<br></blockquote><div> </div><div>LOL! Totally Agree!! (I won&#39;t be able to see them as the ADFS people anymore)</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">
&gt; One question: Since the ADFS it&#39;s always answering with the attribute<br>
&gt; ForceAuth = true in the SAML AuthRequest when we access their WS-<br>
&gt; Federation URL resource, can we do something to prevent the ForceAuth to<br>
&gt; appear or there&#39;s nothing that we can do (us meaning Shib&#39;s Idp) to avoid the<br>
&gt; re-force-auth?<br>
<br>
</span>You can&#39;t do anything about the flag. The simplest solution is probably to point them at an intermediate script or something that that regenerates a new request without the flag, assuming you&#39;re not requiring signed requests, which I&#39;m sure you&#39;re not.<br>
<div class="HOEnZb"><div class="h5"><br></div></div></blockquote><div><br></div><div>Thanks a lot, it makes sense.</div><div><br></div><div>I really appreciate your help!</div><div><br></div><div>Best,</div><div><br></div><div><br></div></div></div></div>