<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body>
<div>
<div dir="ltr">
<div dir="ltr">Surely you just farm this out to an AD based solution, or SAML proxy. This sort of thing is what Defender is built for.</div>
<div dir="ltr">We have ours monitoring everything, plus a separate SIEM solution (I can’t remember what it’s called - I don’t run cybersec) monitoring AD/Entra logins, and you trust a specific tool like that to work out if you’re under attack.</div>
<div dir="ltr"><br>
</div>
<div dir="ltr">HTH</div>
<div dir="ltr">Dave</div>
</div>
</div>
<div id="ms-outlook-mobile-signature">
<div><br>
</div>
Sent from <a href="https://aka.ms/o0ukef">Outlook for iOS</a></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Matt Brennan via users <users@shibboleth.net><br>
<b>Sent:</b> Saturday, April 13, 2024 12:51:03 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Matt Brennan <brennanma@gmail.com><br>
<b>Subject:</b> Shibboleth IdP in a WAF</font>
<div> </div>
</div>
<div>
<table border="0" cellspacing="0" cellpadding="0" align="left" width="100%">
<tbody>
<tr>
<td style="background:#ffb900; padding:5pt 2pt 5pt 2pt"></td>
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5; padding:5pt 4pt 5pt 12pt; word-wrap:break-word">
<div style="color:#222222"><span style="color:#222; font-weight:bold">Caution:</span> Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.
</div>
</td>
</tr>
</tbody>
</table>
<br>
<div>
<div dir="ltr">I was wondering if anyone has any example rules how they configure blocking brute force attempts against the IdP. Certainly we have rules in place to lock out accounts which protects against brute force, but this doesn't stop an attacker who
just wants to wreak havoc by intentionally locking out multiple accounts.
<div><br>
</div>
<div>I've recently been trying to find a way to determine login failures, but with everything I try to do I cannot tell the difference between a failure versus a success and an MFA prompt (since both result in a 302 to execution=e1s2). I don't see any headers
which indicate failure either. </div>
<div><br>
</div>
<div>Currently I'm just monitoring for too many 302s in a short time, but I've had a few legit users get locked out when they log in to multiple services in a short time (i.e. sitting down and starting their day). </div>
<div><br>
</div>
<div>Can anyone else share how they are accomplishing this? Is there a way to add a response header to indicate when a failure occurs?</div>
<div><br>
</div>
<div>TIA!</div>
<div>-Matt</div>
</div>
</div>
</div>
</body>
</html>