<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 14.6667px;"></span></p>
<div>> This question is a bit broad but, does anyone have any experience</div>
<div>> using Shibboleth IDP with Azure ADFS and Azure MFA?</div>
<div><br>
</div>
<div><span style="font-family: Calibri, Helvetica, sans-serif, Helvetica, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 16px;"> </span>Could you be more specific what exactly the
 connection between those</div>
<div>terms should be?</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>Yes. Though, to be honest, I more know what I want and less how / if it can be done.  But, to add some detail:</div>
<div><br>
</div>
<div>1) most of our apps are protected by shibboleth SPs going against shibboleth IDP with LDAP as datasource. No MFA.</div>
<div><br>
</div>
<div>2) some of our apps are protected by shibboleth SPs going against cloud Azure-as-an-IDP. MFA works here and is provided by Azure.</div>
<div><br>
</div>
<div><br>
</div>
<div>We need to rollout MFA to the apps in group #1. </div>
<div><br>
</div>
<div>We could just roll out #2 (Azure as IDP) to all the apps and achieve MFA coverage but Azure as IDP is a lot more restrictive than shibboleth IDP. For various reasons we greatly prefer shibboleth IDP.</div>
<div><br>
</div>
<div>But most our users are doing MFA in Azure for their webmail and they use the MS Authenticator app on their watch or phone and like it. </div>
<div><br>
</div>
<div>So we would prefer to design something where we can use shibboleth as IDP (to keep IT happy) but Azure is --some how-- MFA provider (to keep users happy). That is essentially the ask: shib IDP with azure MFA.</div>
<div><br>
</div>
<div>As I think about it, I think we would less want to use ADFS which I think would be heading in the opposite  direction (Azure login deferring to shibboleth IDP) and more, if possible, setup a shibboleth IDP to use Azure as an external auth source where
 azure also provides MFA?</div>
<div><br>
</div>
<div>Hopefully this detail helps some and that I'm getting enough of the terminology right to explain.</div>
<div><br>
</div>
<div>Appreciate the time. Any suggestions would be appreciate.<br>
<br>
Sean</div>
<p></p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> Thursday, June 28, 2018 2:01:45 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Azure MFA with Shibboleth</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">* Sean Flannery <sean.flannery@jwt.com> [2018-06-28 19:45]:<br>
> This question is a bit broad but, does anyone have any experience<br>
> using Shibboleth IDP with Azure ADFS and Azure MFA?<br>
<br>
Could you be more specific what exactly the connection between those<br>
terms should be?<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>