<div dir="ltr"><div>Hi, <br><br>I am trying to configure my Shibboleth v4 IDP for Research.gov MFA. And I believe I configured everything from my side as NIH federation MFA is working fine. [ Fine means, I do see NIH enforcing "<a href="https://refeds.org/profile/mfa">https://refeds.org/profile/mfa</a>" in "AuthnContextClassRef" in SAML assertion ]. <br><br>But for Researdh.gov I don't see anything like this. Do you have any suggestions what's wrong with my setup? I tried to contact Research.gov support but not getting enough responses. <br><br>Here is what I am getting when I am testing my SSO with Research.gov: <br><br><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<br>                    ID="0000xxxxdcc39b4e5c90862"<br>                    Version="2.0"<br>                    IssueInstant="2025-03-07T15:09:40Z"<br>                    Destination="<a href="https://myhostname/idp/profile/SAML2/POST/SSO">https://myhostname/idp/profile/SAML2/POST/SSO</a>"<br>                    ForceAuthn="false"<br>                    IsPassive="false"<br>                    ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br>                    AssertionConsumerServiceURL="<a href="https://identity.acpt.research.gov/sso/Consumer/metaAlias/research/identity.acpt.research.gov">https://identity.acpt.research.gov/sso/Consumer/metaAlias/research/identity.acpt.research.gov</a>"<br>                    ><br>    <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://identity.acpt.research.gov/sso/sp">https://identity.acpt.research.gov/sso/sp</a></saml:Issuer><br>    <samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<br>                        Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"<br>                        SPNameQualifier="<a href="https://identity.acpt.research.gov/sso/sp">https://identity.acpt.research.gov/sso/sp</a>"<br>                        AllowCreate="true"<br>                        /><br>    <samlp:RequestedAuthnContext xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<br>                                 Comparison="exact"<br>                                 /><br></samlp:AuthnRequest></div><div><br>Thanks in advance! <br><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature">Best,<br>Zico</div></div>