<div dir="ltr"><font color="#000000">Hi Nate,</font><div><font color="#000000"><br></font></div><div><font color="#000000">I am not sure how many are aware of it; Duke University developed its own internal Password-less solution called Duke Unlock.</font></div><div><font color="#000000"><br></font></div><div><a href="https://meetings.internet2.edu/media/medialibrary/2019/12/05/20191210-patel-webauthn.pdf">https://meetings.internet2.edu/media/medialibrary/2019/12/05/20191210-patel-webauthn.pdf</a><font color="#000000"><br></font></div><div><a href="https://www.incommon.org/news/duke-unlock-one-step-multi-factor/">https://www.incommon.org/news/duke-unlock-one-step-multi-factor/</a><br></div><div><font color="#000000"><a href="https://oit.duke.edu/what-we-do/applications/duke-unlock">https://oit.duke.edu/what-we-do/applications/duke-unlock</a></font></div><div><font color="#000000"><br></font></div><div><div style=""><font color="#000000">Best,</font></div><div style=""><font color="#000000"><br></font></div><div style=""><font color="#000000">Nadim El-Khoury</font></div><div style=""><font color="#000000">Director of Networks, Systems, Infrastructure, and Information Security Officer</font></div><div style=""><font color="#000000">Springfield College</font></div><div style=""><font color="#000000">263 Alden Street</font></div><div style=""><font color="#000000">Springfield, MA 01109</font></div><div style=""><font color="#000000">email: <a href="mailto:nel-khoury@springfield.edu" target="_blank" style="">nel-khoury@springfield.edu</a></font></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Sun, Jul 4, 2021 at 8:50 AM Nadim El-Khoury <<a href="mailto:nel-khoury@springfield.edu">nel-khoury@springfield.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Hi Nate,<div><br></div><div>Thank you for the detailed information and steps. I will post back once I get the flow working. </div><div><br></div><div>We are going to use <a href="https://www.trusona.com/why-trusona/passwordless-mfa" target="_blank">Trusona</a> 2FA passwordless solution. In the beginning, they did not provide any integration with Shibboleth, but after talking to other universities and us, they added Shibboleth as one of their supported applications. You might want to look at their solution. </div><div><br></div><div><div>Best,</div><div><br></div><div>Nadim El-Khoury</div><div>Director of Networks, Systems, Infrastructure, and Information Security Officer</div><div>Springfield College</div><div>263 Alden Street</div><div>Springfield, MA 01109</div><div>email: <a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a></div></div><div><br></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jul 2, 2021 at 9:18 PM Nate Klingenstein <<a href="mailto:ndk@signet.id" target="_blank">ndk@signet.id</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Nadim,<br>
<br>
I believe you could set up a flow that does that by presenting a page for username entry, then using a JavaScript comparison against a derived principal(or even the username as entered) in your MFA script as a conditional means to pick which flow to proceed to. Part of the conditional flow example in the Wiki could help, but development of the complete set of flows and scripting will be a meaningful amount of work.<br>
<br>
<a href="https://wiki.shibboleth.net/confluence/display/IDP4/MultiFactorAuthnConfiguration" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP4/MultiFactorAuthnConfiguration</a><br>
<br>
However, I'm also curious how the 2FA/MFA solution works. Usually, I hear 2FA defined as serial presentation of a combination of "something you know" and "something you have" and "something you intrinsically are", and MFA as simultaneous presentation of those. It doesn't sound like "something you know" is a part of this, so I wonder what the two factors look like, given some of the challenges "something you intrinsically are" can present.<br>
<br>
<a href="https://en.wikipedia.org/wiki/Multi-factor_authentication" rel="noreferrer" target="_blank">https://en.wikipedia.org/wiki/Multi-factor_authentication</a><br>
<br>
Take care,<br>
Nate.<br>
<br>
--------<br>
Signet, Inc.<br>
The Art of Access ®<br>
<br>
<a href="https://www.signet.id" rel="noreferrer" target="_blank">https://www.signet.id</a><br>
<br>
-----Original message-----<br>
From: Nadim El-Khoury via users<br>
Sent: Saturday, July 3 2021, 1:00 am<br>
To: <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
Cc: Nadim El-Khoury<br>
Subject: Influence MFA authentication flow based on Username alone for phased 2FA deployment<br>
<br>
Hi Everyone,<br>
<br>
Is there a way to influence MFA authentication flow based on the Username alone?<br>
<br>
We want to phase the deployment of 2FA based on whether the user is part of phase1, phase2, and so forth. Our 2FA is passwordless and does not require the user to enter their username and password.<br>
<br>
So, we want only to display the Username field on the Login page. The user enters their username, and we determine whether to display the password field or send them to our 2FA passwordless SAML setup.<br>
<br>
I read most of the threads about MFA and went over the documentation, and there was one topic where the MFA flow was modified based on relying party.<br>
<br>
Best,<br>
<br>
Nadim El-Khoury<br>
<br>
Director of Networks, Systems, Infrastructure, and Information Security Officer<br>
<br>
Springfield College<br>
<br>
263 Alden Street<br>
<br>
Springfield, MA 01109<br>
<br>
email: <a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a> <mailto:<a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a>><br>
<br>
--<br>
<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
</blockquote></div>
</blockquote></div>