<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 14pt; color: rgb(0, 0, 0);">
Thank you, Scott, for the explanation. I will check if our IdP is  <span style="font-family: Calibri, Helvetica, sans-serif;">
"</span><span style="color: rgb(32, 31, 30); font-family: Calibri, Helvetica, sans-serif; font-size: 14pt; background-color: rgb(255, 255, 255); display: inline !important;">REFEDS MFA profile compliant".</span></div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 14pt; color: rgb(0, 0, 0);">
<span style="color:rgb(32, 31, 30);font-family:"Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, BlinkMacSystemFont, Roboto, "Helvetica Neue", sans-serif;font-size:14.6667px;background-color:rgb(255, 255, 255);display:inline !important"><br>
</span></div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 14pt; color: rgb(0, 0, 0);">
<span style="color: rgb(32, 31, 30); font-family: Calibri, Helvetica, sans-serif; font-size: 14pt; background-color: rgb(255, 255, 255); display: inline !important;"> -Francis</span></div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> 21 February 2022 22:07<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Francis Jayakanth <francis@iisc.ac.in><br>
<b>Subject:</b> Re: Enabling MFA on Shibboleth IDP 4.01</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">External Email<br>
<br>
<br>
On 2/21/22, 11:17 AM, "users on behalf of Francis Jayakanth via users" <users-bounces@shibboleth.net on behalf of users@shibboleth.net> wrote:<br>
<br>
> Does it mean that our IdP should be MFA compliant and that, if it is not, there is no way to gain access to the<br>
> site via the institutional login process?<br>
<br>
There is no such thing as "MFA compliant". There's "REFEDS MFA profile compliant", which involves a determination as to the suitability of a deployment to meet the profile's (incredibly minimal) requirements and then supporting the signaling of the defined
 AuthnContextClassRef value within one's IdP. NIH is requesting that context, so the IdP either understands it, or it fails. Failure is not an error, it's a compliant response to being asked for something it doesn't know how to do.<br>
<br>
You have to understand the IdP's features in the area of context class signaling. and add the necessary configuration for that to work. Doing so is much more complex in the face of using something like Azure, which is deficient in supporting the SAML standard,
 or it would be relatively simple.<br>
<br>
There are HowTos in the wiki about supporting the REFEDS context in general for a local MFA deployment, but I don't know that there are any regarding how to do it with Azure, I imagine some of it is site specific. There are people that use it that could probably
 provide that sort of information, but I'm not among them.<br>
<br>
-- Scott<br>
<br>
<br>
</div>
</span></font></div>
</body>
</html>