<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">I’m a tad confused, over here we have IdP + Duo -> Google and it seems to do what we want (2FA to get access).  Where is the gap that led you to instead go this route?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Dave<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">--<o:p></o:p></p>
<p class="MsoNormal">David Langenberg<o:p></o:p></p>
<p class="MsoNormal">Asst Director, Identity Management<o:p></o:p></p>
<p class="MsoNormal">The University of Chicago<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of
</b>IAM David Bantz<br>
<b>Sent:</b> Monday, October 14, 2019 3:42 PM<br>
<b>To:</b> Michael A Grady <mgrady@unicon.net><br>
<b>Cc:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: FYI: configured GAE + Shibb IdP + Google MFA push<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">2FA for email is a management priority, so IdP first factor and Google's 2nd factor addresses that specific priority. <o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">That holds out hope for SSO via single IdP deploying 2FA for Google for entire UA via Google's 2FA and Duo, selectively, for vastly smaller number of high risk accounts or services. While not ideal, the alternative (which may still be what
 is deployed) is Google authentication and 2FA for Google apps, Shibb IdP for others, most of which are not 2FA protected.<o:p></o:p></p>
</div>
<div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">David<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<p class="MsoNormal">On Mon, Oct 14, 2019 at 12:25 PM Michael A Grady <<a href="mailto:mgrady@unicon.net">mgrady@unicon.net</a>> wrote:<o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<p class="MsoNormal">So as long as the only thing you want 2nd factor for is Google’s own services, that will work. Is that all you needed it for?<o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p> </o:p></p>
<div>
<p class="MsoNormal">Sent from my iPhone<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal" style="margin-bottom:12.0pt">On Oct 14, 2019, at 3:08 PM, IAM David Bantz <<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>> wrote:<o:p></o:p></p>
</blockquote>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class="MsoNormal"><o:p></o:p></p>
<div>
<p class="MsoNormal">FWIW, I was able to set up our "proof of concept" domain <a href="https://urldefense.com/v3/__http:/poc.alaska.edu__;!pWSdj_w3qx0ASw!snpLahpAbueoNopQBVenpq0hFO73MDR8msxpZzZOg_sgWb_7yheXNVR3wXXemrhQeA$" target="_blank">
poc.alaska.edu</a> to use our regular Shibb IdP for authentication and then turn on Google's 2nd factor authN for my account. (So the sequence is go to Google, sign in to
<a href="https://urldefense.com/v3/__http:/poc.alaska.edu__;!pWSdj_w3qx0ASw!snpLahpAbueoNopQBVenpq0hFO73MDR8msxpZzZOg_sgWb_7yheXNVR3wXXemrhQeA$" target="_blank">
poc.alaska.edu</a> which redirects to UA IdP, then upon successful authn and relay to Google, Google pushes prompt for 2nd factor to the Google app on my phone.)<o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">David<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p> <o:p></o:p></p>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="100%" align="center">
</div>
<p>This email has been scanned for spam and viruses by Proofpoint Essentials. Click
<a href="https://urldefense.com/v3/__https:/us2.proofpointessentials.com/index01.php?mod_id=11&mod_option=logitem&mail_id=1571083701-yfT2ankqrNdh&r_address=mgrady*40unicon.net&report=1__;JQ!pWSdj_w3qx0ASw!snpLahpAbueoNopQBVenpq0hFO73MDR8msxpZzZOg_sgWb_7yheXNVR3wXXBgSX-Sg$" target="_blank">
here</a> to report this email as spam.<o:p></o:p></p>
<p class="MsoNormal"><br>
=<o:p></o:p></p>
</div>
</blockquote>
</div>
</div>
</blockquote>
</div>
</div>
</body>
</html>