<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><br id="lineBreakAtBeginningOfMessage"><div><br><blockquote type="cite"><div>On Jan 8, 2025, at 4:41 PM, Cantor, Scott via users <users@shibboleth.net> wrote:</div><br class="Apple-interchange-newline"><div><div><blockquote type="cite">I'm wondering if anyone has deployed Microsoft MFA on an<br>IdP where the IdP is still doing its own password<br>authentication instead of proxying to EntraID.<br></blockquote><br>My understanding was that wasn't possible. If that's untrue, I don't think I'm speaking too far afield in saying we'd be willing to support it.<br><br></div></div></blockquote><div><br></div>The Apereo CAS Server used to support this, because Microsoft used to provide an API for talking to their MFA service. But they pulled that API a few years back. I've not heard anything to make me think there is any chance they will provide that capability again.</div><div><br></div><div>So, bottom line, not going to be possible. You can see that as a definitive statement on this Apereo CAS Github page:</div><div><br></div><div>  <a href="https://github.com/apereo/cas/blob/master/docs/cas-server-documentation/mfa/Configuring-Multifactor-Authentication.md">https://github.com/apereo/cas/blob/master/docs/cas-server-documentation/mfa/Configuring-Multifactor-Authentication.md</a></div><div><br></div><div><br></div><div>p.s. I recall "hearing" that after Microsoft stopped supporting that API, that there was some "roundabout/Rube Goldberg" approach through a Radius server to interact with the MFA service. But I've not heard about that in the last couple of years, and never saw any hard evidence for that as a solution.</div><div><br></div><br><div>
<div>--<br>Michael A. Grady<br>IAM Architect, Unicon, Inc.</div><div><br></div><br class="Apple-interchange-newline">

</div>
<br></body></html>