<div><div><div class="gmail_quote"><div dir="ltr">On Thu, Jun 28, 2018 at 1:33 PM Sean Flannery <<a href="mailto:sean.flannery@jwt.com" target="_blank">sean.flannery@jwt.com</a>> wrote:</div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div id="m_403868529495504505m_-3284848437393056008divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif" dir="ltr"><div dir="auto"></div></div></div><div dir="ltr"><div id="m_403868529495504505m_-3284848437393056008divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif" dir="ltr">
<div dir="auto"><br>
</div>
<div>We could just roll out #2 (Azure as IDP) to all the apps and achieve MFA coverage but Azure as IDP is a lot more restrictive than shibboleth IDP. For various reasons we greatly prefer shibboleth IDP.</div>
<div><br>
</div>
<div>But most our users are doing MFA in Azure for their webmail and they use the MS Authenticator app on their watch or phone and like it. </div>
<div><br>
</div>
<div>So we would prefer to design something where we can use shibboleth as IDP (to keep IT happy) but Azure is --some how-- MFA provider (to keep users happy). That is essentially the ask: shib IDP with azure MFA.</div>
<div><br>
</div>
<div>As I think about it, I think we would less want to use ADFS which I think would be heading in the opposite  direction (Azure login deferring to shibboleth IDP) and more, if possible, setup a shibboleth IDP to use Azure as an external auth source where
 azure also provides MFA?</div></div></div></blockquote><div dir="auto"><br></div></div></div></div><div><div class="gmail_quote"><div dir="auto">Are both ADFS and the Shibboleth IdP using Azure AD as the directory?  One solution would be to authenticate Shibboleth with ADFS, with the Shibboleth IdP being an SP.</div><div dir="auto"><br></div><div dir="auto">But you’d prefer to use the Shibboleth IdP as the primary IdP, there seem to be two options in the documtation.  There appears to be an on-prem option; I don’t know if that’s doable for you, but it has RADIUS and LDAP interfaces.  The latter could likely be used with a few modifications to the existing Shibboleth LDAP authentication modules.  (I thought I had seen where someone had done RADIUS at some point; maybe that was JAAS?). Alternatively, it looks like they have an API: </div><div dir="auto"><div dir="auto"><a href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-sdk">https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-sdk</a></div><div dir="auto"><br></div><div dir="auto">Greg</div></div></div></div><div><div><div class="gmail_quote"><div dir="auto"><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div id="m_403868529495504505m_-3284848437393056008divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif" dir="ltr"><div></div>
<div><br>
</div>
<div>Hopefully this detail helps some and that I'm getting enough of the terminology right to explain.</div>
<div><br>
</div>
<div>Appreciate the time. Any suggestions would be appreciate.<br>
<br>
Sean</div>
<p></p>
</div>
<hr style="display:inline-block;width:98%">
<div id="m_403868529495504505m_-3284848437393056008divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Peter Schober <<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>><br>
<b>Sent:</b> Thursday, June 28, 2018 2:01:45 PM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
<b>Subject:</b> Re: Azure MFA with Shibboleth</font>
<div> </div>
</div></div><div dir="ltr">
<div class="m_403868529495504505m_-3284848437393056008BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="m_403868529495504505m_-3284848437393056008PlainText">* Sean Flannery <<a href="mailto:sean.flannery@jwt.com" target="_blank">sean.flannery@jwt.com</a>> [2018-06-28 19:45]:<br>
> This question is a bit broad but, does anyone have any experience<br>
> using Shibboleth IDP with Azure ADFS and Azure MFA?<br>
<br>
Could you be more specific what exactly the connection between those<br>
terms should be?<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div>
</span></font></div>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div></div></div>