<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<div id="divtagdefaultwrapper" style="font-size: 12pt; color: rgb(0, 0, 0); font-family: Calibri, Helvetica, sans-serif, Helvetica, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">Thanks Janusz (and others for replying).<br>
<br>
I'm not real familiar with OIDC but wouldn't that mean that sites currently protected by our shibboleth SPs would have to change to read their data via the oauth claims from OIDC (as opposed to reading it now via the saml assertions)? I don't consider that
 a huge change, but my group doesn't control all those sites so it would require coordination. 
<br>
<br>
I appreciate the time.<br>
<br>
<br>
<br>
</p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Janusz Ulanowski <janusz.ulanowski@heanet.ie><br>
<b>Sent:</b> Friday, June 29, 2018 5:44:50 AM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Azure MFA with Shibboleth</font>
<div> </div>
</div>
<meta content="text/html; charset=Windows-1252">
<div style="background-color:#FFFFFF">
<div class="x_moz-cite-prefix">Hi,<br>
You can do it by mixing with oidc.<br>
1. when authn must happen on azure<br>
  - setup apache-oidc and register app on azure<br>
  - set default shibb auth (remoteuser)<br>
2. when you have sso on azure to use your shibb for authn then:<br>
   - the same as 1.<br>
   - configure shibb to use Password authn for relying party (azure)<br>
<br>
It worked for me<br>
-- <br>
Janusz<br>
<br>
On 28/06/18 18:45, Sean Flannery wrote:<br>
</div>
<blockquote type="cite">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size: 12pt; color: rgb(0, 0, 0); font-family: Calibri, Helvetica, sans-serif, Helvetica, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols;">
<div>Hello,</div>
<div><br>
</div>
<div>This question is a bit broad but, does anyone have any experience using Shibboleth IDP with Azure ADFS and Azure MFA?
<br>
<br>
The last post I saw on this question was from about a year ago in the forums and it contained some conversations of people looking into it, but no one seemed to have any real experiences with it yet.<br>
<br>
I'm finding a lot of info on Azure as an IDP and Azure with Shibboleth <span style="">
ADFS</span> but nothing that specifically mentions how Azure MFA, which our org uses for webmail, would impact that design.<br>
<br>
If anyone has any experience with that, and wether it does or does not work- I'd appreciate that feedback very much.<br>
<br>
Best<br>
<br>
</div>
</div>
<p style="font-family:'Calibri',arial,sans-serif; font-size:9px">This transmission is intended solely for the person or organization to whom it is addressed and it may contain privileged and confidential information. If you are not the intended recipient you
 should not copy, distribute or take any action in reliance on it. If you believe you received this transmission in error please notify the sender.
</p>
<br>
<fieldset class="x_mimeAttachmentHeader"></fieldset> <br>
</blockquote>
<p><br>
</p>
</div>
</div>
</body>
</html>