<div dir="ltr">Our IdP is configured now to require 2FA for those with a specific value of an "assurance" attribute (based on group membership in the enterprise LDAP directory).<div><br></div><div>Now I've been asked to require 2FA for anyone using a particular service relying on this IdP (it's AWS if that makes any difference). That is, whether or not they would be required to use 2FA based on the assurance attribute, they do need 2FA to get authN asserted to AWS. Is that feasible?</div><div><br></div><div>Seems it should be possible, setting the defaultAuthenticationMethod for this service in relying-party.xml, and the right configuration in multi-context-broker.xml.  For the life of me though I can't keep context and method straight, as the authN "methods" in relying-party.xml look like the "context" names in multi-context-broker.xml.  </div><div><br></div><div>If you've set up something parallel, or have a good idea of how I configure for this result, please enlighten me.  </div><div><br>Thank you,</div><div><br></div><div>David Bantz</div></div>