<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Mar 2, 2017 at 8:57 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">But what is the IdP actually doing with them? It doesn't necessarily care whether the "user identity" it's handling is a user or a device, but in most IDM systems today, devices don't get represented, so there's no identity really express.</blockquote></div><br>I guess I see it as kind of equivalent to "library walk-in" ePA use case.  I feel like that would get implemented for users using trusted devices.</div><div class="gmail_extra"><br></div><div class="gmail_extra">The vendor in question in BlueJeans.  In my conversation with our video conferencing people, it appears as if the only way to make a device available to BlueJeans is to log in from it.  We have a need to make devices that are associated with places (not people) available to this system.  IP based authentication seems like it might be reasonable.</div><div class="gmail_extra"><br></div><div class="gmail_extra">Liam</div></div>