<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-US">Hi
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-US">This is a question for IT or the advanced practioners please<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<table style="border-bottom: 1px solid; border-bottom-color: #B8B8B8;">
        <tbody>
                <tr>
                        <td colspan="4"><span style="font-size: 14pt; font-family: Arial; font-weight: bold; color: #3c3c3b;">Dan Attwood</span></td>
                </tr>
                <tr>
                        <td colspan="4" style="padding-bottom: 2px; border-bottom: 1px solid; border-bottom-color: #B8B8B8;"><span style="font-size: 12pt; font-family: Arial; font-weight; color: #3c3c3b;">BI Reporting Sys Man</span></td>
                </tr>
                <tr>
                        <td rowspan="3"><a href="https://www.midkent.ac.uk"><img alt="College Logo" src="cid:yv5oYERRdUSnLckcKowBAMKC-Logo-Small-Compressed_png" style="width: 80px; height: 66px;" /></a> </td>
                        <td><span style="font-size: 12pt;"><strong><span style="color: #3c3c3b; font-family: Arial;">Main:</span></strong></span></td>
                        <td><span style="font-size: 12pt; font-family: Arial; font-weight; color: #3c3c3b;">+441634383000</span></td>
                        <td rowspan="3">   <a href="https://reports.ofsted.gov.uk/provider/31/130726"><img src="cid:RABGQw4GJESkCFTuGhwAQOfsted_Good_GP_Colour60x60-min_png" /></a>   </td>
                </tr>
                <tr>
                        <td><span style="font-size: 12pt;"><strong><span style="color: #3c3c3b; font-family: Arial;">Direct:</span></strong></span></td>
                        <td><span style="font-size: 12pt; font-family: Arial; font-weight; color: #3c3c3b;">+441634383483</span></td>
                </tr>
                <tr>
                        <td><span style="font-size: 12pt;"><strong><span style="color: #3c3c3b; font-family: Arial;">Web:</span></strong></span></td>
                        <td><span style="font-size: 12pt;"><a href="https://www.midkent.ac.uk" title="MKC Web Page"><span style="color: #3c3c3b; font-family: Arial;">www.midkent.ac.uk</span></a></span></td>
                </tr>
        </tbody>
</table>
<p><span style="line-height:1;"><span style="font-size:9pt; font-family: Arial;">Disclaimer: MidKent College accepts no responsibility for information, errors or omissions in this e-mail and any files transmitted with it, nor for its use or misuse, nor for any act committed or omitted in connection with this communication. If in doubt, please verify the authenticity of the contents with the sender. It is the recipient's responsibility to ensure that appropriate measures are in place to check for software viruses.</span></span></p>

<p><span style="line-height:1;"><span style="font-size:9pt; font-family: Arial;">Confidentiality: This e-mail (including any attachments) is intended only for the recipient(s) named above. It may contain confidential or privileged information and should not be read, copied or otherwise used by any other person unless express permission is given. If you are not a named recipient, please contact the sender and delete the email from your system. It is important that you should not disclose its contents to any other person or copy it for your own or others uses.</span></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Nadim El-Khoury via users<br>
<b>Sent:</b> 07 July 2021 13:09<br>
<b>To:</b> Mak, Steve <makst@upenn.edu>; cantor.2@osu.edu<br>
<b>Cc:</b> Nadim El-Khoury <nel-khoury@springfield.edu>; Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Influence MFA authentication flow based on Username alone for phased 2FA deployment<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<table class="MsoNormalTable" border="1" cellpadding="0" style="background:yellow;border:outset 4.5pt">
<tbody>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal" align="center" style="text-align:center"><strong><span style="font-family:"Calibri",sans-serif">[WARNING]</span></strong><span style="color:black"> This e-mail has been sent to you from outside of MidKent College. Do not click links or
 open attachments unless you know the sender and are expecting the content.</span><o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;?line-height: 12.0pt;background:#FFEB9C’">
 <o:p></o:p></p>
</div>
<div>
<div>
<p class="MsoNormal">Hi Steve, Scott, <o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Thank you for the added information, directions, and what to look for to make sure that the flow works. <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:black">Best,</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:black"> </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:black">Nadim El-Khoury</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:black">Director of Networks, Systems, Infrastructure, and Information Security Officer</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:black">Springfield College</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:black">263 Alden Street</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:black">Springfield, MA 01109</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:black">email: <a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a></span><o:p></o:p></p>
</div>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<p class="MsoNormal">On Tue, Jul 6, 2021 at 2:34 PM Mak, Steve <<a href="mailto:makst@upenn.edu">makst@upenn.edu</a>> wrote:<o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm">
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Nadim,<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Yes my MFA flow does this:<br>
<br>
1. First factor logic -> Do a lookup for something trusted that already contains the principal info or route to Password flow (this is purposefully vague)<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">2. Second factor logic -> Check if it's an app that can't do 2FA and if not then ask the web service if the user from #1 needs to see the 2FA flow (and also checks
 for other things that allow the user to skip the 2FA flow)<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">- Steve<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><b><span lang="EN-US" style="font-size:12.0pt;color:black">From:
</span></b><span lang="EN-US" style="font-size:12.0pt;color:black">Nadim El-Khoury <<a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a>><br>
<b>Date: </b>Tuesday, July 6, 2021 at 2:24 PM<br>
<b>To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>>, "Mak, Steve" <<a href="mailto:makst@upenn.edu" target="_blank">makst@upenn.edu</a>>, Nate Klingenstein <<a href="mailto:ndk@signet.id" target="_blank">ndk@signet.id</a>><br>
<b>Subject: </b>Re: Influence MFA authentication flow based on Username alone for phased 2FA deployment</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Hi Steve,<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Thank you for sharing how you have configured your decision process on whether the user is required to fulfill the 2FA challenge. I am going to presume that the
 user is still required to enter their password first?<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Best,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"><br>
Nadim<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">On Tue, Jul 6, 2021 at 9:57 AM Nate Klingenstein <<a href="mailto:ndk@sudonym.me" target="_blank">ndk@sudonym.me</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-bottom:5.0pt">
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">All neat stuff, Nadim and Steve.  Thanks for sharing.  As one of the greybeards in identity management at this point, it's exciting to see that people have found
 good ways to make biometrics work in practice.<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">I'll still have my old school concerns about the inability to reset one's biometrics, but with the capabilities of modern end user devices and protocols, I think
 those are minimized relative to the challenges of passwords or other credentials in many deployment scenarios, as ably demonstrated in Shilen's presentation and your explanations.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Again, thanks for passing all that along.<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">On Tue, Jul 6, 2021, 6:06 AM Mak, Steve <<a href="mailto:makst@upenn.edu" target="_blank">makst@upenn.edu</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-bottom:5.0pt">
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">I wanted to add onto this discussion since it's related.<br>
<br>
For our 2FA we did something using the custom script in the MFA flow. We have a web service that knows whether a user is required to fulfill the 2FA challenge. I just built a web client inside the script that talks to a local process using http and json that
 fetches that answer.<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Then we route to the 2FA flow based on the return response.<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">The other route we had considered was using grouper entitlements to use an attribute to decide if a user needs to see the 2FA challenge, but we could never find
 a good solution regarding attribute sync delays.<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">The nice thing with the script and controlling the routing internally is we can control what happens when the web service goes down.<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">- Steve<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><b><span lang="EN-US" style="font-size:12.0pt;color:black">From:
</span></b><span lang="EN-US" style="font-size:12.0pt;color:black">users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Nadim El-Khoury via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Reply-To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Date: </b>Tuesday, July 6, 2021 at 7:12 AM<br>
<b>To: </b>Nate Klingenstein <<a href="mailto:ndk@signet.id" target="_blank">ndk@signet.id</a>><br>
<b>Cc: </b>Nadim El-Khoury <<a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a>>, "<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>" <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject: </b>Re: Influence MFA authentication flow based on Username alone for phased 2FA deployment</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Hi Nate,<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">If you want to see how Trusona is currently integrated with our IDP instance. <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">You can go to the link below, type Springfield College, and be redirected to our IDP. You can click on the "Sign In using Trusona." The user is taken to Trusona
 and presented with a QR code. The user would have already registered their phone. Please note that the current setup is for testing, and I am still working on modifying the login page and the flow.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"><a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ffedsp-stage.ccp.xcal.tv%2Fauth%3Fcontinue%3Dhttps%3A%2F%2Ffedsp-stage.ccp.xcal.tv%2FparseJWT%26tenant%3Dtester%26usePing%3Dtrue%26xoc-school-i&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919669168%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=XsrmD2gXxu1BV%2FqxLLzZN7m%2BUXkOCc56OTuCATzvepk%3D&reserved=0" target="_blank">https://fedsp-stage.ccp.xcal.tv/auth?continue=https://fedsp-stage.ccp.xcal.tv/parseJWT&tenant=tester&usePing=true&xoc-school-i</a><o:p></o:p></span></p>
</div>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Best,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Nadim<o:p></o:p></span></p>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">On Sun, Jul 4, 2021 at 9:32 AM Nadim El-Khoury <<a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-bottom:5.0pt">
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">Hi Nate,</span><span lang="EN-US"><o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">I am not sure how many are aware of it; Duke University developed its own internal Password-less solution called Duke Unlock.</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"><a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmeetings.internet2.edu%2Fmedia%2Fmedialibrary%2F2019%2F12%2F05%2F20191210-patel-webauthn.pdf&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919679106%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=kcRd6oo7u1D9pSH6SXOWXy4%2BmjWjR3Irjktc7q%2F8GD8%3D&reserved=0" target="_blank">https://meetings.internet2.edu/media/medialibrary/2019/12/05/20191210-patel-webauthn.pdf</a><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"><a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.incommon.org%2Fnews%2Fduke-unlock-one-step-multi-factor%2F&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919679106%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=Vk8AML0cFr6STbWzs4kPL6OQJvPiq6rxPFWGnytRNII%3D&reserved=0" target="_blank">https://www.incommon.org/news/duke-unlock-one-step-multi-factor/</a><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black"><a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Foit.duke.edu%2Fwhat-we-do%2Fapplications%2Fduke-unlock&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919689062%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=BLMMr3Ipf4WkW4mb%2B95qKiYXZ0QE9PTlSLJWlH4vjtE%3D&reserved=0" target="_blank">https://oit.duke.edu/what-we-do/applications/duke-unlock</a></span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">Best,</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">Nadim El-Khoury</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">Director of Networks, Systems, Infrastructure, and Information Security Officer</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">Springfield College</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">263 Alden Street</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">Springfield, MA 01109</span><span lang="EN-US"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US" style="color:black">email: <a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a></span><span lang="EN-US"><o:p></o:p></span></p>
</div>
</div>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">On Sun, Jul 4, 2021 at 8:50 AM Nadim El-Khoury <<a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-bottom:5.0pt">
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Hi Nate,<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Thank you for the detailed information and steps. I will post back once I get the flow working. <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">We are going to use
<a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.trusona.com%2Fwhy-trusona%2Fpasswordless-mfa&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919689062%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=w5JWC67MWa7nROhUScT02vc%2B4RNht6jRv975zBIdgtw%3D&reserved=0" target="_blank">
Trusona</a> 2FA passwordless solution. In the beginning, they did not provide any integration with Shibboleth, but after talking to other universities and us, they added Shibboleth as one of their supported applications. You might want to look at their solution. <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Best,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Nadim El-Khoury<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Director of Networks, Systems, Infrastructure, and Information Security Officer<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Springfield College<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">263 Alden Street<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">Springfield, MA 01109<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">email: <a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a><o:p></o:p></span></p>
</div>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US"> <o:p></o:p></span></p>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">On Fri, Jul 2, 2021 at 9:18 PM Nate Klingenstein <<a href="mailto:ndk@signet.id" target="_blank">ndk@signet.id</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-bottom:5.0pt">
<p class="MsoNormal" style="mso-margin-top-alt:auto;margin-bottom:12.0pt"><span lang="EN-US">Nadim,<br>
<br>
I believe you could set up a flow that does that by presenting a page for username entry, then using a JavaScript comparison against a derived principal(or even the username as entered) in your MFA script as a conditional means to pick which flow to proceed
 to.  Part of the conditional flow example in the Wiki could help, but development of the complete set of flows and scripting will be a meaningful amount of work.<br>
<br>
<a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fdisplay%2FIDP4%2FMultiFactorAuthnConfiguration&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919699017%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=%2FtPkI3lqkV1aLaEVYxIUJ84C0ZVg9CugKQk7u4QbRsA%3D&reserved=0" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP4/MultiFactorAuthnConfiguration</a><br>
<br>
However, I'm also curious how the 2FA/MFA solution works.  Usually, I hear 2FA defined as serial presentation of a combination of "something you know" and "something you have" and "something you intrinsically are", and MFA as simultaneous presentation of those. 
 It doesn't sound like "something you know" is a part of this, so I wonder what the two factors look like, given some of the challenges "something you intrinsically are" can present.<br>
<br>
<a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FMulti-factor_authentication&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919699017%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=B3KWHiBHVNs5dyi4MPFJn7bU6zB0dplw5QwRqN3C3aU%3D&reserved=0" target="_blank">https://en.wikipedia.org/wiki/Multi-factor_authentication</a><br>
<br>
Take care,<br>
Nate.<br>
<br>
--------<br>
Signet, Inc.<br>
The Art of Access ®<br>
<br>
<a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.signet.id%2F&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919708973%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=aEWLYdhtmmabcz2CDTT3j2LbdH5WSeTN3BHMjOzXlzs%3D&reserved=0" target="_blank">https://www.signet.id</a><br>
<br>
-----Original message-----<br>
From: Nadim El-Khoury via users<br>
Sent: Saturday, July 3 2021, 1:00 am<br>
To: <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
Cc: Nadim El-Khoury<br>
Subject: Influence MFA authentication flow based on Username alone for phased 2FA deployment<br>
<br>
Hi Everyone,<br>
<br>
Is there a way to influence MFA authentication flow based on the Username alone?<br>
<br>
We want to phase the deployment of 2FA based on whether the user is part of phase1, phase2, and so forth. Our 2FA is passwordless and does not require the user to enter their username and password.<br>
<br>
So, we want only to display the Username field on the Login page. The user enters their username, and we determine whether to display the password field or send them to our 2FA passwordless SAML setup.<br>
<br>
I read most of the threads about MFA and went over the documentation, and there was one topic where the MFA flow was modified based on relying party.<br>
<br>
Best,<br>
<br>
Nadim El-Khoury<br>
<br>
Director of Networks, Systems, Infrastructure, and Information Security Officer<br>
<br>
Springfield College<br>
<br>
263 Alden Street<br>
<br>
Springfield, MA 01109<br>
<br>
email: <a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a> <mailto:<a href="mailto:nel-khoury@springfield.edu" target="_blank">nel-khoury@springfield.edu</a>><br>
<br>
--<br>
<br>
For Consortium Member technical support, see <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919708973%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=S6UojHDeAbiNoL7sdDaZXx76jmgvArX6EKqWSMTgLgg%3D&reserved=0" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><o:p></o:p></span></p>
</blockquote>
</div>
</blockquote>
</div>
</blockquote>
</div>
</div>
</div>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">--
<br>
For Consortium Member technical support, see <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919718942%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=YYO0WbV3iDzZnjqU2T01Sh9kChNCnL%2FkeMm1Q3QwlPU%3D&reserved=0" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><o:p></o:p></span></p>
</blockquote>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-US">--
<br>
For Consortium Member technical support, see <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Cdan.attwood%40midkent.ac.uk%7Cd4713c060d084f95ca9208d941401ea6%7C157678f9b5f84952af3282449dc16f58%7C0%7C0%7C637612565919718942%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=YYO0WbV3iDzZnjqU2T01Sh9kChNCnL%2FkeMm1Q3QwlPU%3D&reserved=0" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><o:p></o:p></span></p>
</blockquote>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</body>
</html>