<div dir="ltr"><div>Scott,</div><div><br></div><div>Thank you for the information, I've corrected the idp.authn.flows to be MFA only. From your explanations, I can say that something clicked and I began to understand how the authentication flows are built, how to enable them properly and how they are defined through mfa-authn-config.xml as well as general-authn.xml. Currently, the system is working as I want it to and I believe I have figured out how to override the global configurations within relying-party.xml across my individual services. Thank you for taking the time to answer my questions.<br></div><div><br></div><div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr">-Jeremiah Garmatter, Systems Administrator<br></div><div>-Ohio Northern University, Class of 2020<br></div><div><a href="mailto:j-garmatter@onu.edu" target="_blank">j-garmatter@onu.edu</a></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Jul 28, 2020 at 2:28 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 7/28/20, 2:16 PM, "users on behalf of Mak, Steve" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:makst@upenn.edu" target="_blank">makst@upenn.edu</a>> wrote:<br>
<br>
> This list has warned in the past and I will warn you as well.<br>
><br>
> idp.authn.flows= MFA|Duo|Password<br>
><br>
> This line is enabling a possible MFA bypass in your IdP.<br>
<br>
That's correct, that documentation is wrong.<br>
<br>
> My IdP only has idp.authn.flows=MFA<br>
<br>
Using the MFA feature generally involves enabling only that flow. In rare cases, when there are "other" methods unrelated to the MFA rules such as X.509 or SPNEGO, you might have them both active, but generally that's going to cause problems later and it's best to control the combination of options directly with the MFA feature.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>