<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I should have specified that the SP was throwing the error that there was no authn context, since the IdP was indeed disregarding the unspecified request.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Turns out though that the problem was that despite requesting "unspecified or better" what it really wanted was urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport, and Azure AD was passing back urn:oasis:names:tc:SAML:2.0:ac:classes:Password.
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I just mapped it and everything looks fine now.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
-Mat<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Friday, October 8, 2021 10:18 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Odd SP behavior re authn context</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">On 10/8/21, 3:20 PM, "users on behalf of mat houser" <users-bounces@shibboleth.net on behalf of mhouser@uwm.edu> wrote:<br>
<br>
> In the authn request it's requesting this:<br>
<br>
The IdP defaults to ignoring "urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified" in any requests (it's a set of ignored values that's in the configuration in a bean called shibboleth.IgnoredContexts), so if an SP requested that, the IdP would act as though
nothing was requested and would NOT return an error.<br>
<br>
But yes, it's nonsensical to ask for "better than unspecified", that makes no sense as you correctly inferred.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=04%7C01%7Cmhouser%40uwm.edu%7Cdd56b63cb1d64b304c3e08d98ad37ef9%7C0bca7ac3fcb64efd89eb6de97603cf21%7C0%7C0%7C637693463252958852%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=SbrwOW3w7FmsUkeviM0FTP2URZ0bMb50GVCUWSzBg5A%3D&reserved=0">
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=04%7C01%7Cmhouser%40uwm.edu%7Cdd56b63cb1d64b304c3e08d98ad37ef9%7C0bca7ac3fcb64efd89eb6de97603cf21%7C0%7C0%7C637693463252958852%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=SbrwOW3w7FmsUkeviM0FTP2URZ0bMb50GVCUWSzBg5A%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>