<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;">Yep. That was the right hint! Thanks for the quick support!<br id="lineBreakAtBeginningOfMessage"><div>
<meta charset="UTF-8"><div>--<br>Florian Ritterhoff - Zentrale IT<br>Hochschule München University of Applied Sciences<br>Lothstraße 34, 80335 München, G2.21a<br>T +49 89 1265-1745</div>
</div>
<div><br><blockquote type="cite"><div>On 19. Apr 2024, at 16:24, Cantor, Scott via users <users@shibboleth.net> wrote:</div><br class="Apple-interchange-newline"><div><div>I guess if your actual goal here is "don't require MFA but pick a different context for it if it's used", then that would be addressed by setting defaultAuthenticationMethods to both the "special" value and something else like Password or PPT, and that can allow the IdP to bypass MFA if it's not required.<br><br>A lot of this is very site-specific in terms of how MFA is being applied and when, but suffice to say the weight map is not your answer here.<br><br>-- Scott<br><br><br>-- <br>For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br></div></div></blockquote></div><br></body></html>