<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <br>
    <br>
    <div class="moz-cite-prefix">On 01/11/2018 06:44 PM, Paul B. Henson
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:MWHPR0101MB3151B1B38DBFDF195819824AD2170@MWHPR0101MB3151.prod.exchangelabs.com">
      <blockquote type="cite">
        <pre wrap="">From: David Walker
Sent: Thursday, January 11, 2018 9:00 AM

The second group would be applications that tailor the access they provide
based on the type of authentication performed, perhaps later requesting
(and requiring) MFA when sensitive/risky transactions are attempted.
</pre>
      </blockquote>
      <pre wrap="">
Well, actually, in my classification that is a completely new category I hadn't even considered yet 8-/. Although doesn't that just work out-of-the-box; initially the application asserts a password context and then later forces a reauth requiring an MFA context?</pre>
    </blockquote>
    <br>
    Probably not germane to where this thread is going, but right, it
    requires the application to control authentication events based on
    what the user is doing.<br>
    <br>
    <blockquote type="cite"
cite="mid:MWHPR0101MB3151B1B38DBFDF195819824AD2170@MWHPR0101MB3151.prod.exchangelabs.com">
      <pre wrap="">My second group are applications that once you authenticate successfully you get to use without any future context changes, but that will do MFA if a user can but not fail if they can't.

Thanks…

--
Paul B. Henson  |  (909) 979-6361  |  <a class="moz-txt-link-freetext" href="http://www.cpp.edu/~henson/">http://www.cpp.edu/~henson/</a>
Operating Systems and Network Analyst  |  <a class="moz-txt-link-abbreviated" href="mailto:henson@cpp.edu">henson@cpp.edu</a>
California State Polytechnic University  |  Pomona CA 91768



</pre>
    </blockquote>
    <br>
  </body>
</html>