<div dir="ltr">I would suggest looking into going the other directions. Have Entra be a federated client of Shibboleth. <div>If an application requires MFA, they route the requests to Entra where you should (in theory) be able to apply the higher security protocols.</div><div>If MFA not required, the application can go direct to Shibboleth.</div><div><br></div><div>Tim</div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Wed, Jan 8, 2025 at 6:34 PM Michael Grady via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><br id="m_4351174022807053352lineBreakAtBeginningOfMessage"><div><br><blockquote type="cite"><div>On Jan 8, 2025, at 4:41 PM, Cantor, Scott via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:</div><br><div><div><blockquote type="cite">I'm wondering if anyone has deployed Microsoft MFA on an<br>IdP where the IdP is still doing its own password<br>authentication instead of proxying to EntraID.<br></blockquote><br>My understanding was that wasn't possible. If that's untrue, I don't think I'm speaking too far afield in saying we'd be willing to support it.<br><br></div></div></blockquote><div><br></div>The Apereo CAS Server used to support this, because Microsoft used to provide an API for talking to their MFA service. But they pulled that API a few years back. I've not heard anything to make me think there is any chance they will provide that capability again.</div><div><br></div><div>So, bottom line, not going to be possible. You can see that as a definitive statement on this Apereo CAS Github page:</div><div><br></div><div>  <a href="https://github.com/apereo/cas/blob/master/docs/cas-server-documentation/mfa/Configuring-Multifactor-Authentication.md" target="_blank">https://github.com/apereo/cas/blob/master/docs/cas-server-documentation/mfa/Configuring-Multifactor-Authentication.md</a></div><div><br></div><div><br></div><div>p.s. I recall "hearing" that after Microsoft stopped supporting that API, that there was some "roundabout/Rube Goldberg" approach through a Radius server to interact with the MFA service. But I've not heard about that in the last couple of years, and never saw any hard evidence for that as a solution.</div><div><br></div><br><div>
<div>--<br>Michael A. Grady<br>IAM Architect, Unicon, Inc.</div><div><br></div><br>

</div>
<br></div>-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>