<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body>
    <font face="Helvetica, Arial, sans-serif">Thanks, very helpful.<br>
      <br>
      Don<br>
    </font><br>
    <div class="moz-cite-prefix">On 4/4/23 4:36 PM, Peter Schober via
      users wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:ZCyKQquodgtX4h8J@aco.net">
      <pre class="moz-quote-pre" wrap="">CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
________________________________

* Lohr, Donald A - lohrda via users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a> [2023-04-04 18:50]:
</pre>
      <blockquote type="cite">
        <pre class="moz-quote-pre" wrap="">I think what I am after is not being asked for correctly and thus likely not
being read correctly, because I still feel like I have unanswered questions.
</pre>
      </blockquote>
      <pre class="moz-quote-pre" wrap="">
No, you just keep ignoring or misreading or not understanding what
several people have been telling you here.

1. There is no integration to use Okta's MDA from your Shibboleth IDP
   the way one exists for Duo. (The "API" Scott mentioned Duo having
   for this but Okta not offering.)
2. The only way to still achieve Okta MDA with the Shibboleth IDP is by
   activating the built-in SAML SP in the Shib IDP and integrating *that*
   SAML SP with Okta (SAML proxying). Okta then only knows your
   Shibboleth IDP/SP combo, it doesn't need to know anything about
   federation, InCommon or R&S.
3. Anything you integrate directy with the Okta IDP you configure in
   the Okta IDP, with buttons/icons and with or without MFA as desired.
4. Everything else -- including all of the less enterprisey research and
   teaching tools, licensed e-journals, federation, interfederation,
   InCommon, eduGAIN, etc. -- you keep on your Shib IDP as it is today.
5. People access those (item 4) protected resources same way they ever
   have. When they need to log in they'll select your (Shib) IDP for
   login (same as ever) and get redirected there. At that point --
   instead of displaying the usual username/password field -- the Shib
   IDP/SP combo will send the request along to Okta and Okta either
   enforces MFA (because you want to use it for anything that comes in
   "via Shibboleth") or it doesn't (because you don't want MFA for
   anything coming in from your Shib IDP).

So you do have your answer:
It is possible if you give up the login screen from your Shibboleth
IDP and have it defer any and all authentication business to Okta. (If
you don't use any consent functionality in your Shib IDP this would
mean people never even see anything from your Shib IDP -- only Okta
will be seen.)
If you do not want to do this (for whatever reason) then you cannot
use Okta MFA with your Shibboleth IDP. As simple as that.

HTH,
-peter
--
For Consortium Member technical support, see <a class="moz-txt-link-freetext" href="https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!N6YHze6lT7thMl0!NCvT1tgYI8FPsQxFH9KH2_P3QlblKvrkBxF5vs_pGMSbN8hyeYAdAOAWI86IIdYDUsSzYIWQkmDwRk4T$">https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!N6YHze6lT7thMl0!NCvT1tgYI8FPsQxFH9KH2_P3QlblKvrkBxF5vs_pGMSbN8hyeYAdAOAWI86IIdYDUsSzYIWQkmDwRk4T$</a>
To unsubscribe from this list send an email to <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a>
</pre>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>