<div dir="ltr">Enabling forcedAuthenticationSupported for authn/External in IDP4<br clear="all"><div>All,</div><div><br></div><div>We are stuck in a bit of a hard place. We are currently using authn/External with an external CAS as our first factor in authn/MFA. We are planning on replacing that with  authn/Password in the nearish future (next month), but we have an SP that *needs* to go live earlier than that (next week).</div><div><br></div><div>This SP requires that we allow forcedAuthentication -- it's the only one we have run into that requires this, and they do not offer a QA environment (they also will not tie their production to our QA environment). This vendor does not seem to actually care if authentication is forced or not, but the SP software they are using seems to default to it on, and they cannot turn it off.</div><div><br></div><div>When this SP tries to connect, I get the following error in my logs:</div><div><br></div><div>Profile Action TransitionMultiFactorAuthentication: Targeted login flow 'authn/External' does not support forced re-authentication<br></div><div><br></div><div>I have looked through the documentation, and I have already tried setting p:forceAuthn="true" in the relying-party.xml, and it seemed *not* to resolve things. I presume that the error being generated comes earlier in the login process than relying-party.xml does.</div><div><br></div><div>Is it as simple as adding idp.authn.external.forcedAuthenticationSupported = true to the authn.properties to enable this?<br><br>I believe that while the authn/External will just check to see if the current CAS cookie is valid and not prompt the user, we *will* be using Duo with settings to "always prompt", so we will be honoring the spirit of forcedAuthentication -- users will still have to verify their identity with at least one factor before accessing the SP.</div><div><br></div><div>Please let me know if I am on the right track, or missing something.</div><div><br></div><div>Thanks,</div><div>Jeff</div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><pre cols="72">Jeff Chapin,</pre>Panther eSports Adviser            <br>Systems/Applications Administrator<br>ITS-IS, University of Northern Iowa<br>Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a> </div></div></div></div></div>