<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">Sean,</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">The last time I investigated it was awhile ago when they were primarily using a product they acquired known as "Phonefactor".  I don't know how much things have evolved from there, but I couldn't even have a coherent
 conversation about integration.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">At that time, I felt that they don't think of themselves as an independent second factor.  They think of themselves as your complete identity and authentication provider.  The idea of abstracting one of those factors
 away seemed totally foreign to their architectural vision.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">It's been about 6 months since I had any meaningful conversations with them about this.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Thanks,</p>
<p style="margin-top:0;margin-bottom:0">Nate.</p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Sean Flannery <sean.flannery@jwt.com><br>
<b>Sent:</b> Thursday, June 28, 2018 1:33:13 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Azure MFA with Shibboleth</font>
<div> </div>
</div>
<meta content="text/html; charset=us-ascii">
<style type="text/css" style="display:none">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top:0; margin-bottom:0"><span style="color:rgb(33,33,33); font-family:wf_segoe-ui_normal,"Segoe UI","Segoe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; font-size:14.6667px"></span></p>
<div>> This question is a bit broad but, does anyone have any experience</div>
<div>> using Shibboleth IDP with Azure ADFS and Azure MFA?</div>
<div><br>
</div>
<div><span style="font-family:Calibri,Helvetica,sans-serif,Helvetica,EmojiFont,"Apple Color Emoji","Segoe UI Emoji",NotoColorEmoji,"Segoe UI Symbol","Android Emoji",EmojiSymbols; font-size:16px"> </span>Could you be more specific what exactly the connection
 between those</div>
<div>terms should be?</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>Yes. Though, to be honest, I more know what I want and less how / if it can be done.  But, to add some detail:</div>
<div><br>
</div>
<div>1) most of our apps are protected by shibboleth SPs going against shibboleth IDP with LDAP as datasource. No MFA.</div>
<div><br>
</div>
<div>2) some of our apps are protected by shibboleth SPs going against cloud Azure-as-an-IDP. MFA works here and is provided by Azure.</div>
<div><br>
</div>
<div><br>
</div>
<div>We need to rollout MFA to the apps in group #1. </div>
<div><br>
</div>
<div>We could just roll out #2 (Azure as IDP) to all the apps and achieve MFA coverage but Azure as IDP is a lot more restrictive than shibboleth IDP. For various reasons we greatly prefer shibboleth IDP.</div>
<div><br>
</div>
<div>But most our users are doing MFA in Azure for their webmail and they use the MS Authenticator app on their watch or phone and like it. </div>
<div><br>
</div>
<div>So we would prefer to design something where we can use shibboleth as IDP (to keep IT happy) but Azure is --some how-- MFA provider (to keep users happy). That is essentially the ask: shib IDP with azure MFA.</div>
<div><br>
</div>
<div>As I think about it, I think we would less want to use ADFS which I think would be heading in the opposite  direction (Azure login deferring to shibboleth IDP) and more, if possible, setup a shibboleth IDP to use Azure as an external auth source where
 azure also provides MFA?</div>
<div><br>
</div>
<div>Hopefully this detail helps some and that I'm getting enough of the terminology right to explain.</div>
<div><br>
</div>
<div>Appreciate the time. Any suggestions would be appreciate.<br>
<br>
Sean</div>
<p></p>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> Thursday, June 28, 2018 2:01:45 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Azure MFA with Shibboleth</font>
<div> </div>
</div>
<div class="x_BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="x_PlainText">* Sean Flannery <sean.flannery@jwt.com> [2018-06-28 19:45]:<br>
> This question is a bit broad but, does anyone have any experience<br>
> using Shibboleth IDP with Azure ADFS and Azure MFA?<br>
<br>
Could you be more specific what exactly the connection between those<br>
terms should be?<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</body>
</html>