<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"Segoe UI Emoji";
panose-1:2 11 5 2 4 2 4 2 2 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0cm;
margin-right:0cm;
margin-bottom:0cm;
margin-left:36.0pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
p.xmsonormal, li.xmsonormal, div.xmsonormal
{mso-style-name:x_msonormal;
margin:0cm;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.EmailStyle28
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:1622111912;
mso-list-type:hybrid;
mso-list-template-ids:-1467329144 134807553 134807555 134807557 134807553 134807555 134807557 134807553 134807555 134807557;}
@list l0:level1
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:38.25pt;
text-indent:-18.0pt;
font-family:Symbol;}
@list l0:level2
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:74.25pt;
text-indent:-18.0pt;
font-family:"Courier New";}
@list l0:level3
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:110.25pt;
text-indent:-18.0pt;
font-family:Wingdings;}
@list l0:level4
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:146.25pt;
text-indent:-18.0pt;
font-family:Symbol;}
@list l0:level5
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:182.25pt;
text-indent:-18.0pt;
font-family:"Courier New";}
@list l0:level6
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:218.25pt;
text-indent:-18.0pt;
font-family:Wingdings;}
@list l0:level7
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:254.25pt;
text-indent:-18.0pt;
font-family:Symbol;}
@list l0:level8
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:290.25pt;
text-indent:-18.0pt;
font-family:"Courier New";}
@list l0:level9
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:326.25pt;
text-indent:-18.0pt;
font-family:Wingdings;}
ol
{margin-bottom:0cm;}
ul
{margin-bottom:0cm;}
--></style>
</head>
<body lang="EN-GB" link="#0563C1" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Hi<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">I think you may have misunderstood (unless of course I have since I’ve not actually used it yet!).<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">My understanding of the flow is:
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<ul style="margin-top:0cm" type="disc">
<li class="MsoListParagraph" style="margin-left:2.25pt;mso-list:l0 level1 lfo1"><span style="mso-fareast-language:EN-US">an SP directs user to their Shib IdP (or they do IdP initiated auth)<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:2.25pt;mso-list:l0 level1 lfo1"><span style="mso-fareast-language:EN-US">If the user doesn’t have a Shib session, the Shib IdP sends user to Azure AD for authentication purposes (inc MFA if applicable)
<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:2.25pt;mso-list:l0 level1 lfo1"><span style="mso-fareast-language:EN-US">Shib IdP receives authentication result<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:2.25pt;mso-list:l0 level1 lfo1"><span style="mso-fareast-language:EN-US">Shib IdP sends SAML Response to SP<o:p></o:p></span></li></ul>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">The Shib IdP is simply authenticating the user against Azure AD rather than traditional LDAP/others. The Shib IdP is acting like an SP to the Azure AD IdP.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">I’m sure Overt can do a better job of explaining than I can though!
</span><span style="font-family:"Segoe UI Emoji",sans-serif;mso-fareast-language:EN-US">😊</span><span style="mso-fareast-language:EN-US"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">I appreciate this isn’t a direct answer to Vincent’s problem (i.e. how to integrate Azure MFA directly in to Shib auth process), but it is an alternative way to do this probably worth consideration.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">I really can’t say enough about how much value we’ve had from moving to using Overt’s hosted solution. The dashboard makes so many tasks easier, they do any required upgrades and patches, they have
developed it at zero cost based on my own feedback and their support has been excellent and often goes beyond what many others would provide for the same cost. By the way, I am in no way affiliated with them or get any incentives – I’m just a happy customer
who already has way too many things to do and this saves me time </span><span style="font-family:"Segoe UI Emoji",sans-serif;mso-fareast-language:EN-US">😊</span><span style="mso-fareast-language:EN-US"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Hope this helps<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Andy<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:silver">______________________________</span><b><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F"><o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F">Andrew Turner<o:p></o:p></span></b></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F">Senior Infrastructure Analyst<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F">Digital Technology Services<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F">Sheffield Hallam University<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Joseph Fischetti<br>
<b>Sent:</b> 16 November 2020 12:18<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Shibboleth Idp 4+ MFA: is Azure MFA possible? If so, how?<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0cm"><em><span style="font-family:"Calibri",sans-serif;color:black;background:mistyrose">CAUTION: This message was sent from outside the University, purportedly from
<a href="mailto:users-bounces@shibboleth.net"><span style="font-style:normal">users-bounces@shibboleth.net</span></a> .</span></em><span style="color:black;background:yellow"><o:p></o:p></span></p>
<p style="margin:0cm"><strong><i><span style="font-family:"Calibri",sans-serif;color:black;background:mistyrose">Please check the sender is legitimate</span></i></strong><em><span style="font-family:"Calibri",sans-serif;color:black;background:mistyrose"> before
responding. Please treat any links or attachments with care - do not follow or open them unless you are sure they are genuine.</span></em><span style="color:black;background:yellow"><o:p></o:p></span></p>
<p style="margin:0cm"><i><span style="color:green"><br>
<br>
</span></i><o:p></o:p></p>
<p style="margin:0cm"><i><span style="color:green"><br>
<br>
</span></i><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Arial",sans-serif;color:black">In the scenario that Andy describes, Microsoft is still running your IdP, they're just delegating authentication to your shibboleth IdP.
<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Arial",sans-serif;color:black">This doesn't necessarily accomplish what the original poster was looking for. Any SP pointed to Shib will not be protected with MFA. Only those pointed
to Azure will get MFA prompted.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">At this point in time, I do believe Duo is the only turn key solution. I had developed a plugin (pre 4.0) so the IdP could do native TOTP MFA. It worked well, but with it comes all
sorts of other token management issues you would have to deal with. <o:p></o:p></span></p>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="divRplyFwdMsg">
<p class="MsoNormal"><b><span style="color:black">From:</span></b><span style="color:black"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> on behalf of Turner, Andrew P <<a href="mailto:A.P.Turner@shu.ac.uk">A.P.Turner@shu.ac.uk</a>><br>
<b>Sent:</b> Monday, November 16, 2020 4:46:34 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Subject:</b> RE: Shibboleth Idp 4+ MFA: is Azure MFA possible? If so, how?</span>
<o:p></o:p></p>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</div>
<div>
<p style="background:#FF6700"><b><span style="font-size:12.0pt;color:black">[EXTERNAL EMAIL]</span></b><o:p></o:p></p>
<div>
<div>
<p class="xmsonormal">Hi<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">We’re just rolling out Azure MFA and are in a similar situation to yourself. We have Shibboleth doing lots of SSO and ADFS doing Azure AD/Office 365 + a growing number of other apps.
<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">We took the decision a couple of years ago to go with <a href="https://www.overtsoftware.com/">
Overt Software’s</a> hosted (though I think you can run on-prem too if you prefer) Shibboleth IdP for which they have a “<a href="https://www.overtsoftware.com/adfs-shibboleth-bridge/">bridge</a>” between Shib and Azure AD. This means you can point your Shib
IdP at Azure AD for authentication, and hence benefit from Azure MFA.<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">They also have their own MFA solution that can be used with their IdP. If you went that route you could do the “bridging” the other way and use the Shib IdP to create a session on Azure AD for SSO to that too.<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">They also provide a great dashboard for reporting on and managing the config (and it integrates their MFA solution I think too). It’s also been very reasonably priced (for us at least) and I certainly wouldn’t go back to managing our own
IdP installations.<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">We haven’t quite made the jump to use the bridge yet (as we don’t have consistent identities across the directory used by Shib and Azure AD) but we do plan to. I know at least one other Uni in the UK that have.<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">I’m sure other suppliers are also available <span style="font-family:"Segoe UI Emoji",sans-serif">
😊</span><o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">Andy<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<div>
<p class="xmsonormal"><span style="font-family:"Arial",sans-serif;color:silver">______________________________</span><o:p></o:p></p>
<p class="xmsonormal"><b><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F">Andrew Turner</span></b><o:p></o:p></p>
<p class="xmsonormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F">Senior Infrastructure Analyst</span><o:p></o:p></p>
<p class="xmsonormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F"> </span><o:p></o:p></p>
<p class="xmsonormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F">Digital Technology Services</span><o:p></o:p></p>
<p class="xmsonormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#7F7F7F">Sheffield Hallam University</span><o:p></o:p></p>
</div>
<p class="xmsonormal"> <o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="xmsonormal"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Vincent Feyaerts<br>
<b>Sent:</b> 16 November 2020 08:25<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Subject:</b> Shibboleth Idp 4+ MFA: is Azure MFA possible? If so, how?</span><o:p></o:p></p>
</div>
</div>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">Hi,</span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US"> </span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">Currently we have a Shibboleth IdP 3.x running with Microsoft ADFS as slave for Microsoft Products like Office 365. We’re upgrading to Shib IdP 4 soon. Since we are an educational institution, I don’t think it’s realistic
to have it reversed, where Shibboleth is the slave and ADFS is the master. We’ve done some extensive finetuning for SP’s that have special requirements, and we are part of a number of federations with their own requirements, I don’t think we can emulate that
IdP behaviour with ADFS.</span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US"> </span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">So now we are looking into MFA. Duo is, from a Shibboleth perspective, by far the easiest to implement. It’s already there. But since we use a lot of Microsoft products, Azure MFA has been mentioned as well. This question
has been asked before, but this information is old, and to be honest, the answers are not 100% clear. So, is there any realistic approach to integrating Azure MFA with a Shibboleth 4 IdP? This would be custom code I guess, to be developed by somebody we pay.
But does Azure MFA even expose an API these days to make that possible? And more importantly, can we assume that they will continue to provide this API? Is anyone looking to implement such a solution?</span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US"> </span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">In the past I read somewhere the following statement: Microsoft doesn’t want to integrate with our IdP, they want to be your IdP :) Was that true? And is it still true? I think Azure MFA will probably integrate great
with ADFS and therefore Office and Teams and whatnot, I’m worried about the other non-MS stuff.</span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US"> </span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">Another, unrelated question: is there any timeline for the release of IdP 4.1?</span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US"> </span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">Thank you</span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">Vincent Feyaerts</span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">Network administrator</span><o:p></o:p></p>
<p class="xmsonormal"><span lang="EN-US">University of Antwerp</span><o:p></o:p></p>
</div>
</div>
</div>
</div>
</body>
</html>