<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
We've hit this recently too with the wider push of passkeys in Entra.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Only one SP found so far, which in their request has the following:</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
    <samlp:RequestedAuthnContext Comparison="exact"></div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
        <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
    </samlp:RequestedAuthnContext></div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
I think the issue being Entra only allows a comparison of "exact" or leaving the comparison property out completely. Shibboleth is behaving exactly as designed and is proxying the request to Entra. Entra is where the issue lies.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
As it's only one SP for us in a 1-2-1 relationship, we're asking if they can remove the Comparison. Any more come up and it might get interesting.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Chris.</div>
<div><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>From:</b> users <users-bounces@shibboleth.net> on behalf of Mark Cairney via users <users@shibboleth.net><br>
<b>Sent:</b> Monday, August 03, 2026 13:16<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Mark Cairney <Mark.Cairney@ed.ac.uk><br>
<b>Subject:</b> Issues with Passkey logins via Entra in SAML proxy mode. </div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-size: 11pt;">External email to Cardiff University - Take care when replying/opening attachments or links.<br>
Nid ebost mewnol o Brifysgol Caerdydd yw hwn - Cymerwch ofal wrth ateb/agor atodiadau neu ddolenni.<br>
<br>
<br>
<br>
Hi,<br>
<br>
We've had reports of issues logging into services protected by our<br>
Shibboleth IdP when using alternative authn methods like Passkeys from<br>
Entra in SAML proxy mode.<br>
<br>
The error in Entra is 'Authentication method 'MultiFactor,Fido' by which<br>
the user authenticated with the service doesn't match requested<br>
authentication method 'Password, ProtectedTransport'. Contact the<br>
Shibboleth-Live application owner.'<br>
<br>
Unfortunately I don't see any obvious error logs in the Shibboleth IdP<br>
side which suggests the issue is between the Entra IdP and the<br>
Shibboleth IdP (in SP mode).<br>
<br>
<br>
I've seen some documentation e.g.<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/3503587329/Supporting+the+REFEDS+MFA+Profile+V5" id="OWA15fb97f6-e0dc-6603-7094-969ddfe782c3" class="OWAAutoLink" data-auth="NotApplicable">https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FKB%2Fpages%2F3503587329%2FSupporting%2Bthe%2BREFEDS%2BMFA%2BProfile%2BV5&data=05%7C02%7Cgrovescd%40cardiff.ac.uk%7Cb28af5cf4add42fcb40f08def159194d%7Cbdb74b3095684856bdbf06759778fcbc%7C1%7C0%7C639213562142482841%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=hfZmSWJ8qa2FVJDF3qDIJkDYnN%2FmWUIQzn4xnZyQQ%2Bs%3D&reserved=0</a><br>
refer to the idp.authn.MFA.supportedPrincipals key but from what I can<br>
tell that is only applicable if you're using the MFA login flow not the<br>
SAML login flow used in SAML proxy mode.<br>
<br>
<br>
Has anyone else seen this behaviour? While we're not seeing a huge<br>
number of issues being reported because of this (and we have a<br>
workaround i.e. use traditional password + MFA to login) I'm slightly<br>
concerned we might see more and more issues like this as these<br>
alternative authn methods become more popular and recommended.<br>
<br>
<br>
Kind regards,<br>
<br>
Mark<br>
<br>
<br>
<br>
--<br>
/****************************<br>
<br>
Mark Cairney<br>
ITI Enterprise Services<br>
Information Services<br>
University of Edinburgh<br>
<br>
Tel: 0131 650 6565<br>
Email: Mark.Cairney@ed.ac.uk<br>
<br>
*******************************/<br>
<br>
The University of Edinburgh is a charitable body, registered in Scotland, with registration number SC005336.<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" id="OWA09380753-bb5c-3560-573b-d6288b55e56d" class="OWAAutoLink" data-auth="NotApplicable">
https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cgrovescd%40cardiff.ac.uk%7Cb28af5cf4add42fcb40f08def159194d%7Cbdb74b3095684856bdbf06759778fcbc%7C1%7C0%7C639213562142533533%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Pswd34ytLnTVmXu9SNSusW77LHPUnDlSUbbMBeUAkQI%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</body>
</html>