<div dir="ltr">We've been proxying to Azure for a bit and are handling REFEDS MFA requests with it as well. I put the code snippet we use in the How-To article: <div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD">https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD</a><br></div><div><br></div><div>It's the same mechanism Tony described, but using values that'll have meaning in Azure.</div><div><br></div><div>-Jeff</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Jun 7, 2021 at 3:29 PM mat houser <<a href="mailto:mhouser@uwm.edu">mhouser@uwm.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">It looks like the initial thing that breaks is that AzureAD doesn't<br>
recognize the <a href="https://refeds.org/profile/mfa" rel="noreferrer" target="_blank">https://refeds.org/profile/mfa</a> context as a valid<br>
authentication method at all. Error text is:<br>
<br>
AADSTS50130: The claim value(s) '<a href="https://refeds.org/profile/mfa" rel="noreferrer" target="_blank">https://refeds.org/profile/mfa</a>' cannot be interpreted as known auth method(s).<br>
<br>
I'm not entirely sure what the potentially known auth methods are in the<br>
Azure tenant, since I only have access to the Shib IdP. I can verify<br>
that putting the MFA profile in the ignored contexts will at least allow<br>
the user to authenticate successfully, but the response will of course<br>
just have the Password context.<br>
<br>
I'm prototyping this in 4.1 at the moment, and it looks like some of how<br>
that would be handled is different now, but that definitely gives me a<br>
better sense of what to look for.<br>
<br>
Thank you!<br>
<br>
-mat<br>
<br>
-- <br>
-------------<br>
mat:houser<br>
<a href="mailto:mhouser@uwm.edu" target="_blank">mhouser@uwm.edu</a><br>
uwm:uits:iam-support<br>
-------------<br>
<br>
On Mon, 7 Jun 2021, Tony Skalski via users wrote:<br>
<br>
Are you referring to the fact that the SP is requesting the<br>
<a href="https://refeds.org/profile/mfa" rel="noreferrer" target="_blank">https://refeds.org/profile/mfa</a> AuthnContextClassRef but Azure is returning<br>
something like "urn:oasis:names:tc:SAML:2.0:ac:classes:Password"?<br>
<br>
I dealt with a similar situation with proxying to Google - whose IdP only<br>
returns "urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified". See my email<br>
to the list from Feb 24 subject: "addDefaultPrincipals vs<br>
PrincipalProxyResponseMappings". I solved it by adjusting<br>
the PrincipalProxyResponseMappings in conf/authn/authn-comparison.xml -<br>
basically telling the IdP<br>
that urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified is as good<br>
as urn:oasis:names:tc:SAML:2.0:ac:classes:Password.<br>
<br>
If there is a way to get Azure to implement <a href="https://refeds.org/profile/mfa" rel="noreferrer" target="_blank">https://refeds.org/profile/mfa</a><br>
that would be preferable. IIRC someone on one of the Shib NIH MFA calls<br>
mentioned that Microsoft was working on this, but I could be misremembering<br>
things. My solution is not optimal as it somewhat misrepresents the<br>
authentication (in our case MFA is enforced by Google for all accounts),<br>
but I had no hope that Google was going to fix it anytime soon.<br>
<br>
ajs<br>
<br>
On Fri, Jun 4, 2021 at 2:45 PM mat houser <<a href="mailto:mhouser@uwm.edu" target="_blank">mhouser@uwm.edu</a>> wrote:<br>
<br>
> Hello all,<br>
><br>
> We're working on proxying our Shib IdP to Azure mostly to get our<br>
> student population enrolled in an MFA solution. Everything appears to be<br>
> working properly except for the <a href="https://refeds.org/profile/mfa" rel="noreferrer" target="_blank">https://refeds.org/profile/mfa</a> business<br>
> breaking things when the user hits the Azure login page.<br>
><br>
> I saw that there was a thread around January on this topic, but is there<br>
> any documentation around on what we would need to do to proxy requests<br>
> from SPs that are requiring the MFA context, or does anybody have any<br>
> examples of how other institutions have addressed this issue?<br>
><br>
> Thanks in advance,<br>
><br>
> -Mat<br>
><br>
> --<br>
> -------------<br>
> mat:houser<br>
> <a href="mailto:mhouser@uwm.edu" target="_blank">mhouser@uwm.edu</a><br>
> uwm:uits:iam-support<br>
> -------------<br>
> --<br>
> For Consortium Member technical support, see<br>
> <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
><br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div dir="ltr">Jeffrey Williams </div><div dir="ltr">Identity & Access Engineer<br>Identity & Access Services<br><a href="https://its.uncg.edu" target="_blank">https://its.uncg.edu</a></div></div><div dir="ltr"><br></div><div dir="ltr"><img src="https://uncgcdn.blob.core.windows.net/email/UNCGLogo.png"><br></div></div></div></div></div></div></div></div></div>