<div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Mon, Aug 1, 2016 at 4:53 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:</div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
The IdP can default in the form of authentication to use based on a RelyingParty override, see the defaultAuthenticationMethods property on any of the SSO profile configurations. The CAS login config should have that property.<br></blockquote><div><span style="line-height:1.5"><br></span></div><div><span style="line-height:1.5">It does and that's the method that we use to selectively enable/disable 2FA for select services. I would recommend defining a "2fa" group and tag those services in your ServiceRegistry bean, then you can use a RelyingPartyByGroup strategy to enable it for a number of services.</span><br></div><div><br></div><div>M<a href="mailto:users-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>