<html><body><div dir="ltr">Our IT helpdesk reports failed attempts to login to a service (“DemandTools by Validity”) and provided screen shots of what appears to be our IdP (Shibb v 4.0) login page embedded in a vendor web page. The service is neither federated nor locally (1:1) configured. It seems to piggy-back or otherwise co-opt a different Salesforce service that relies on our IdP. Further confounding me, DemandTools documentation states that SSO is done via OAuth only (<a href="https://community.validity.com/customers/s/article/DemandTools-Login-Options">https://community.validity.com/customers/s/article/DemandTools-Login-Options</a>). How is a non-federated service we’ve never heard of able to get a response from the IdP embedded on their web page, and allegedly allow (OAuth) logins “sometimes” as long as Duo MFA is not invoked? <div><br></div><div dir="ltr">David St. Pierre Bantz</div><div dir="ltr">U Alaska</div></div></body></html>