<div dir="ltr"><div>Are you referring to the fact that the SP is requesting the <a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a> AuthnContextClassRef but Azure is returning something like "urn:oasis:names:tc:SAML:2.0:ac:classes:Password"?<br></div><div><br></div><div>I dealt with a similar situation with proxying to Google - whose IdP only returns "urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified". See my email to the list from Feb 24 subject: "addDefaultPrincipals vs PrincipalProxyResponseMappings". I solved it by adjusting the PrincipalProxyResponseMappings in conf/authn/authn-comparison.xml - basically telling the IdP that urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified is as good as urn:oasis:names:tc:SAML:2.0:ac:classes:Password.</div><div><br></div><div>If there is a way to get Azure to implement <a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a> that would be preferable. IIRC someone on one of the Shib NIH MFA calls mentioned that Microsoft was working on this, but I could be misremembering things. My solution is not optimal as it somewhat misrepresents the authentication (in our case MFA is enforced by Google for all accounts), but I had no hope that Google was going to fix it anytime soon.</div><div> </div><div>ajs</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jun 4, 2021 at 2:45 PM mat houser <<a href="mailto:mhouser@uwm.edu" target="_blank">mhouser@uwm.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hello all,<br>
<br>
We're working on proxying our Shib IdP to Azure mostly to get our<br>
student population enrolled in an MFA solution. Everything appears to be<br>
working properly except for the <a href="https://refeds.org/profile/mfa" rel="noreferrer" target="_blank">https://refeds.org/profile/mfa</a> business<br>
breaking things when the user hits the Azure login page.<br>
<br>
I saw that there was a thread around January on this topic, but is there<br>
any documentation around on what we would need to do to proxy requests<br>
from SPs that are requiring the MFA context, or does anybody have any<br>
examples of how other institutions have addressed this issue?<br>
<br>
Thanks in advance,<br>
<br>
-Mat<br>
<br>
--<br>
-------------<br>
mat:houser<br>
<a href="mailto:mhouser@uwm.edu" target="_blank">mhouser@uwm.edu</a><br>
uwm:uits:iam-support<br>
-------------<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><b>Tony Skalski</b></div><div dir="ltr">System Administrator | IT</div><div dir="ltr"><img src="https://docs.google.com/uc?export=download&id=0B8pehFb2jk1VTlJUMXNxQzlUZ0k&revid=0B8pehFb2jk1VR0ZGVzBjRksvU1NMQUdwSzNIa05Ea08ydjFFPQ" width="200" height="77"><br></div><div dir="ltr"><b>Office: </b><a href="tel:(507)786-3227" target="_blank">507-786-3227</a></div><div dir="ltr">1510 St. Olaf Avenue Northfield, MN 55057</div><div dir="ltr"><a href="http://stolaf.edu" target="_blank">stolaf.edu</a></div><div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div>