<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body>
    <font face="Helvetica, Arial, sans-serif">It seems that if apps are
      in the Okta portal are still configured against Shibboleth IdP,
      that yes SAML proxying between Okta and Shib IdP is the method.
      But that assumes that all apps have an icon in the Okta portal.<br>
      <br>
      Professors point their students research/periodicals sites and SSO
      login works because of InCommon Federation membership. There is no
      way all of these will get an icon in the Okta portal. If MFA is
      still a goal for these Shibboleth protected applications, does
      anyone know if Shibboleth IdP can be configured to use Okta's MFA
      solution?<br>
      <br>
      Thanks,<br>
      Don<br>
    </font><br>
    <div class="moz-cite-prefix">On 4/4/23 10:19 AM, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:546CE5F2-42EC-4028-9239-D700E61F0434@osu.edu">
      <pre class="moz-quote-pre" wrap="">CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
________________________________

Most likely it relies on fully devolving all authentication to Okta via SAML proxying, in which case I'm sure it works, modulo Okta's lousy SAML compliance. Duo is an outlier in supplying just the second factor with a custom API.

-- Scott


</pre>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>