<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<br>
<br>
<div class="moz-cite-prefix">On 01/11/2018 06:44 PM, Paul B. Henson
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:MWHPR0101MB3151B1B38DBFDF195819824AD2170@MWHPR0101MB3151.prod.exchangelabs.com">
<blockquote type="cite">
<pre wrap="">From: David Walker
Sent: Thursday, January 11, 2018 9:00 AM
The second group would be applications that tailor the access they provide
based on the type of authentication performed, perhaps later requesting
(and requiring) MFA when sensitive/risky transactions are attempted.
</pre>
</blockquote>
<pre wrap="">
Well, actually, in my classification that is a completely new category I hadn't even considered yet 8-/. Although doesn't that just work out-of-the-box; initially the application asserts a password context and then later forces a reauth requiring an MFA context?</pre>
</blockquote>
<br>
Probably not germane to where this thread is going, but right, it
requires the application to control authentication events based on
what the user is doing.<br>
<br>
<blockquote type="cite"
cite="mid:MWHPR0101MB3151B1B38DBFDF195819824AD2170@MWHPR0101MB3151.prod.exchangelabs.com">
<pre wrap="">My second group are applications that once you authenticate successfully you get to use without any future context changes, but that will do MFA if a user can but not fail if they can't.
Thanks…
--
Paul B. Henson | (909) 979-6361 | <a class="moz-txt-link-freetext" href="http://www.cpp.edu/~henson/">http://www.cpp.edu/~henson/</a>
Operating Systems and Network Analyst | <a class="moz-txt-link-abbreviated" href="mailto:henson@cpp.edu">henson@cpp.edu</a>
California State Polytechnic University | Pomona CA 91768
</pre>
</blockquote>
<br>
</body>
</html>