<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">The one option that people haven’t mentioned is signing authentication requests. I don’t know whether that’s an option in your environment, but it’s the alternative.<div class=""><br class=""><div><blockquote type="cite" class=""><div class="">On May 23, 2016, at 11:47, Eric Goodman <<a href="mailto:Eric.Goodman@ucop.edu" class="">Eric.Goodman@ucop.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">My (additional) assumption has always been that if you want to use ForceAuthn in this way that you need to audit the IdPs to ensure this behavior, or at least document it clearly to the IdP leveraging your service, since it's so common for IdPs to be out of compliance or to be in compliance in meaningless ways (e.g., kerb/IWA).<span class="Apple-converted-space"> </span></span><br style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=""></div></blockquote></div><br class=""></div></body></html>