<div dir="ltr"><div>Well, for us, we've been looking at adding MFA to many of our commodity services (Google, Box, O365, Canvas) which consequently all happen to be behind our shibb IdP. As such, we're not interested in offloading the login and need something practical for the masses (cost wise). RSA themselves were the first to tell us we'd never afford SecurID for the whole campus (no surprise there), but quickly turned the convo to their Adaptive Authentication as their obtainable MFA using the typical phone and sms stuff but "better" with its adaptive abilities. Anyway, I pretty much had formed the same opinion Scott, but before I wrote off their empty promises of working with shibb and not offloading our login as the cries of despite sales people, i just wanted to see if anyone had looked at it more in depth than I have (though my doubts remain strong).<br><br></div><div>Thanks,</div>-Rob<br><br><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Jul 6, 2015 at 2:34 PM, Bryan Wooten <span dir="ltr"><<a href="mailto:bryan.wooten@utah.edu" target="_blank">bryan.wooten@utah.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br>
<br>
Bryan Wooten<br>
Email: <a href="mailto:bryan.wooten@utah.edu">bryan.wooten@utah.edu</a><br>
<span class=""><br>
> Their answer to the (IMHO bogus) MFA solutions now flooding the market is the Adaptive thing.<br>
<br>
</span>This statement intrigues me. Bogus MFA Solutions flooding the market, are you refering to 1. phone apps in general / 2. Google stuff / 3. other?<br>
<br>
If it is phones apps in general that you do not consider to be real MFA can you state why you believe that from a technical perspective?<br>
<br>
Thanks,<br>
<br>
Bryan<br>
<div class="HOEnZb"><div class="h5"><br>
-----Original Message-----<br>
From: users [mailto:<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>] On Behalf Of Cantor, Scott<br>
Sent: Monday, July 06, 2015 9:47 AM<br>
To: Shib Users<br>
Subject: Re: RSA Adaptive Authentication<br>
<br>
On 7/6/15, 11:23 AM, "users on behalf of Rob Gorrell" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:rwgorrel@uncg.edu">rwgorrel@uncg.edu</a>> wrote:<br>
<br>
>I was wondering if anyone out there is doing/has done any work towards integrating RSA's Adaptive Authentication solution (their answer to MFA... risk based authentication w/step up) to a shibb IdP for primary auth?<br>
<br>
Well, I would say that RSA's answer to MFA is SecurID, and it works great but is outrageously expensive (the tokens aren't but the license is). Their answer to the (IMHO bogus) MFA solutions now flooding the market is the Adaptive thing.<br>
<br>
Most of the risk-based stuff is really about forcing authentication to a proprietary platform instead of supporting standards. As such, they don't tend to offer APIs you can actually implement against, they force you to offload the login to that system. So from a Shibboleth PoV, you're looking at an agent + RemoteUser type thing. I wouldn't swear they don't have an API, but I would bet they will make it hard to find/use.<br>
<br>
They also increasingly of course bundle their SAML support and proxy portal solutions into those RBA platforms (RSA's is called VIP I think) so they're basically in competition rather than complementary.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><div>Robert W. Gorrell<br>Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div></div>
</div>