<div dir="ltr">I am trying to implement "Integration-Specific Principal Sets"  from this documentation page:<br><a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631604/DuoAuthnConfiguration">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631604/DuoAuthnConfiguration</a> <br><br>I see others have had fun with this over the years -- now it's my turn...<br>We have already deployed the "Multiple Duo Integrations", and our use is almost identical to the example:  we have a couple of services that should get the SpecialDuo, and everything else gets the DefaultDuo.  We now need to implement the Distinct Principal Sets.<br><br>Also, we did update our Duo for the Universal Prompt.  I am not finding a description of the Distinct Principal Sets specifically for DuoOIDC.  I <i><b>think</b></i> I have adapted the setup instructions from Old Duo correctly:  listed all the SupportedPrincipals anywhere I can find that they are configured, turned off addDefaultPrincipals, etc etc.  I have learned that the order of the DuoIntegrationList is very important.  In the log, I can see the IDP is searching for my SpecialDuo integration, but it's still getting lost when doing SSO and sorting thru results.<br><br>I did also find this page in the Shib Knowledge Base, which mentions a bug in the DuoOIDC, and a workaround.  I've added that workaround:<br><a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1474297850/Supporting+the+REFEDS+MFA+Profile+V4#Supporting-Multiple-Duo-Policies">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1474297850/Supporting+the+REFEDS+MFA+Profile+V4#Supporting-Multiple-Duo-Policies</a><br><br>Still not there..<br>Does anyone know of any other documentation specifically for the DuoOIDC version of this functionality?  Or a newer description?  Did anyone run into issues/pitfalls implementing this that might help me?  anything specific to DuoOIDC besides the aforementioned bug?<br><br>BTW we are running IDP 4.2.1 (yes, I know...)<br><br>Joanne<br><br>---<br><br>Joanne Schwendner<br>Identity Services<br>Office of Information Technology<br>Brown University<br><input name="virtru-metadata" type="hidden" value="{"email-policy":{"disableCopyPaste":false,"disablePrint":false,"disableForwarding":false,"enableNoauth":false,"expandedWatermarking":false,"expires":false,"sms":false,"expirationNum":1,"expirationUnit":"days","isManaged":false,"persistentProtection":false},"attachments":{},"compose-id":"16","compose-window":{"secure":false}}"><div><br></div></div>