<div dir="ltr">We've implemented 2FA opt-in internal to our campus SSO.<div>Our IDP is currently using our campus SSO (Cosign) for authentication.</div><div><br></div><div>We've received a request to update the authnContext to reflect when someone has authenticated using 2FA because of opt-in (instead of only showing it if the SP has requested a different context).</div><div><br></div><div>Would it be possible / is it reasonable to assert a different authnContext based on the factors satisfied by the external SSO?  The Cosign SP does reveal to the server environment what factors have been satisfied, and we could try to pass that into Tomcat.</div><div><br></div><div>Liam</div></div>