<div dir="ltr"><div dir="ltr">On Mon, Mar 28, 2022 at 2:28 PM Wessel, Keith <<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>> wrote:<br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US" style="overflow-wrap: break-word;">
<div class="gmail-m_4963705948084242190WordSection1">
<p class="MsoNormal">I’ll add to Scott’s reply and share my little cheating method. We’re currently proxying to ADFS with the SAML proxy. However, I have my MFA config set up with a checkFirstFactor script, similar to the checkSecondFactor script that shipped
 with the IdP. The sends the user to the SAML proxy flow for the first factor if it’s a browser. Ifit’s non-browser, it sends it down the old non-proxied flow of built-in password and Duo. This, of course, means two very different authentication mechanisms
 for browser vs. non-browser, but since cookies and sessions aren’t typically shared between browser and ECP (I can’t think of a case where they are), it works fine.</p></div></div></blockquote><div><br></div><div>I had thought something similar, since we deployed the "checkSecondFactor"-type flow before our current configuration.  However, UNCG has transitioned from Duo to Azure for its MFA service, which is no longer available as a standalone option.  We're also mandated by the state to use MFA, so we couldn't direct them down a non-MFA flow.</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div lang="EN-US" style="overflow-wrap: break-word;"><div class="gmail-m_4963705948084242190WordSection1"><p class="MsoNormal"><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Keith<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0in 0in">
<p class="MsoNormal"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> <b>On Behalf Of
</b>Jeffrey Williams via users<br>
<b>Sent:</b> Friday, March 25, 2022 3:29 PM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Cc:</b> Jeffrey Williams <<a href="mailto:jfwillia@uncg.edu" target="_blank">jfwillia@uncg.edu</a>><br>
<b>Subject:</b> ECP on an idp configured for Azure Proxy (+MFA)<u></u><u></u></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">We've been running our IDP's proxied to Azure for some time and have recently received our first request to have an integration with an ECP client.  At the moment, we have the single proxied flow to Azure(+Azure MFA).  <u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">I was curious to know if anyone has handled ECP-type authn to an IDP that is proxying authn to Azure?  <u></u><u></u></p>
<div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<p class="MsoNormal">-- <u></u><u></u></p>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal">Jeffrey Williams <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Identity & Access Engineer<br>
Identity & Access Services<br>
<a href="https://urldefense.com/v3/__https:/its.uncg.edu__;!!DZ3fjg!oFmJ0b0A58sf0GdkoHmtGDQVNfkRibr87M67QEXM3JjWwNY-JzgRXb33jByegG0v0g$" target="_blank">https://its.uncg.edu</a><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="border:1pt solid windowtext;padding:0in"><img border="0" width="100" height="100" style="width: 1.0416in; height: 1.0416in;" id="gmail-m_4963705948084242190Picture_x0020_1" src="cid:17fd1cbfac9bef104ff1" alt="Image removed by sender."></span><u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>

</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div dir="ltr">Jeffrey Williams </div><div dir="ltr">Identity & Access Engineer<br>Identity & Access Services<br><a href="https://its.uncg.edu" target="_blank">https://its.uncg.edu</a></div></div><div dir="ltr"><br></div><div dir="ltr"><img src="https://uncgcdn.blob.core.windows.net/email/UNCGLogo.png"><br></div></div></div></div></div></div></div></div></div></div>