<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    The second group would be applications that tailor the access they
    provide based on the type of authentication performed, perhaps later
    requesting (and requiring) MFA when sensitive/risky transactions are
    attempted.<br>
    <br>
    David<br>
    <br>
    <br>
    <div class="moz-cite-prefix">On 01/11/2018 08:24 AM, Peter Schober
      wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:20180111162401.GV29183@aco.net">
      <pre wrap="">* Paul B. Henson <a class="moz-txt-link-rfc2396E" href="mailto:henson@cpp.edu"><henson@cpp.edu></a> [2018-01-10 22:40]:
</pre>
      <blockquote type="cite">
        <pre wrap="">Applications will fall into three groups; those that do not need MFA
at all, those that will use MFA if available but still work with
just a password otherwise, and those that strictly require MFA and
will fail if it does not succeed. I'm not sure yet where this
application delineation information will be stored.
</pre>
      </blockquote>
      <pre wrap="">
I may be restarting what Andrew and Tom already said but AFAIU that
second group of service doesn't exist: Either the service requires MFA
(and states that much in its request or in your local config) or it
doesn't (meaning it will take what it gets).

Not sure that helps (or is accurate) but maybe reducing the possible
states to two (force MFA or don't) makes this easier for you?

-peter
</pre>
    </blockquote>
    <br>
  </body>
</html>