<div dir="ltr">Thanks, I will look into 

AuthnContextClassRef  and 

defaultAuthenticationMethods  and see if I can get this figured out.<div><br></div><div>Jeff</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Jun 18, 2024 at 8:56 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> The issue is that Portal uses a Duo profile that allows user to<br>
> be remembered for a full day, and the Java application is<br>
> supposed to force the user to run Duo each time they log in.<br>
<br>
You need to use separate Duo integrations (which you did), but you also have to attach different custom AuthnContextClassRef custom Principals to the integration objects, and select them in a script on the basis of which one satisfies a given request.<br>
<br>
Then you need drive that by attaching requirements with the defaultAuthenticationMethods profile setting so that the selection of the integration to use for Duo will be based on what the service needs.<br>
<br>
There are examples of that in the multiple integrations section of the Duo docs.<br>
<br>
> I'm assuming I am missing a 'force auth' setting somewhere -<br>
<br>
ForceAuthn is meant to bypass SSO entirely, that's not what you're asking about.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div><br clear="all"><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><pre cols="72">Jeff Chapin,</pre>Panther eSports Adviser            <br>Systems/Applications Administrator<br>ITS-IS, University of Northern Iowa<br>Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a> </div></div></div></div>