<div dir="ltr">Is there a setting to make the v3 IdP completely start over when it receives a forceAuthn?  In our setup, we allow users to elect to force Duo for shib logins.  The way we accomplish this is to use Password flow for InitialAuthn and then provide the IdP with only Duo as the only allowed AuthnContext for that user.  We then setup the Duo AuthnContext to be equivalent to PasswordProtectedTransport and all is well.  Unfortunately, in our testing we have turned up that a later forceAuthn request causes only the Duo flow to re-fire.  I understand why this is happening, but was wondering if there was some setting I could change that would instead cause a forceAuthn request to also fire the InitialAuthn flow and re-calculate from there?<div><br></div><div>Dave<br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr"><div>David Langenberg<div>Identity & Access Management Architect</div><div>The University of Chicago</div></div></div></div>
</div></div>