<div dir="ltr">Been asked by Management essentially <br>"CAS appears able to use Authenticator for MFA SSO; why not Shibboleth?"<br><br><div>raised in the context of merging our SSO operation (to reduce complexity to maintain and enhance user experience); most of our apps and federation access rely on Shibb, but Banner ERP and closely related apps use CAS. Independently, CISO hopes to require MFA for administrative access to Banner ERP, and hopes to do it without licensing Duo (purely cost consideration).</div><div><br></div><div>From what I can tell, the Google Authenticator in Apereo CAS (<a href="https://apereo.github.io/cas/5.1.x/installation/GoogleAuthenticator-Authentication.html">https://apereo.github.io/cas/5.1.x/installation/GoogleAuthenticator-Authentication.html</a>) makes CAS an MFA <i>provider</i> maintaining device registrations, secret keys, etc. (but not supporting PUSH AFAICT), so fundamentally different from Shibb Duo plugin.</div><div><br>I'm asking for sanity check of my understanding, any updates on possible Authenticator/Shibboleth integration and additional considerations to inform management/executive decisions re SSO and MFA for Banner.</div><div><br></div><div>David Bantz</div><div>UA OIT IAM</div></div>