<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<span style="color: rgb(0, 0, 0);">I used the duo admin api guide (</span><span style="color: rgb(0, 0, 0);"><a href="https://duo.com/docs/adminapi#authentication-logs" data-outlook-id="50cc097e-9215-4d42-ac71-a4fe62f542d2">https://duo.com/docs/adminapi#authentication-logs</a>)</span><span style="color: rgb(0, 0, 0);">.
 They list all of the currently possible MFA types in the  "factors" key.</span></div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<span style="color: rgb(0, 0, 0);"><br>
</span></div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<span style="color: rgb(0, 0, 0);">- Steve</span></div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="mail-editor-reference-message-container">
<div style="padding: 3pt 0in 0in; border-width: 1pt medium medium; border-style: solid none none; border-color: rgb(181, 196, 223) currentcolor currentcolor;">
<div style="text-align: left; font-family: Aptos; font-size: 12pt; color: black;">
<b>From: </b>users <users-bounces@shibboleth.net> on behalf of Michael Grady via users <users@shibboleth.net><br>
<b>Date: </b>Monday, August 24, 2026 at 5:14 PM<br>
<b>To: </b>Shib Users <users@shibboleth.net><br>
<b>Cc: </b>Michael Grady <mgrady@unicon.net><br>
<b>Subject: </b>Re: authn context comparison per relying party<br>
<br>
</div>
</div>
<div id="mail-editor-reference-message-body">
<div class="ms-outlook-mobile-reference-message skipProofing">
<meta name="Generator" content="Microsoft Exchange Server">
</div>
<div class="PlainText" style="font-size: 11pt;">Is there an "authoritative/up-to-date" list of "factor" values that Duo returns? I've had trouble surfacing anything that I was convinced was current and accurate, and more concerningly, thought I saw something
 that suggested Duo might consider "factor" to be deprecated.<br>
<br>
The AMR value sets Duo are returning appear to me to be useless, as everything from standard Duo Push thru to the most secure methods return the same 3 values:<br>
<br>
  ["mfa", "pop", "user"]<br>
<br>
and does not distinguish if Remember Me was used (if in place, you just get the value set from what was used to establish it in the first place.)<br>
<br>
> On Aug 24, 2026, at 1:26 PM, Scott Cantor via users <users@shibboleth.net> wrote:<br>
><br>
><br>
><br>
>> On Aug 24, 2026, at 1:54 PM, Mak, Steven via users <users@shibboleth.net> wrote:<br>
>><br>
>> Bobby,<br>
>><br>
>> We ended up solving this by using an alternate method that Salesforce supports - a custom resolved attribute 'salesforceAMR'. This felt like a much better fit than trying to do very weird things with the ACCR.<br>
><br>
> I think I suggested that option to somebody also. It's certainly better in some sense than misusing the SAML or OpenID features the way they are.<br>
><br>
> -- Scott<br>
><br>
> --<br>
> For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!IBzWLUs!RoJN5TqJgxIqBjxs0ZTf5glsku1fHX05K56av_eI8jtYfx61kOu_Kf6ytqqRoII_uddkzKyXCVx8YY3i$" data-outlook-id="19ae216b-953c-4a1f-8f4e-936243d3b6d1">
https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!IBzWLUs!RoJN5TqJgxIqBjxs0ZTf5glsku1fHX05K56av_eI8jtYfx61kOu_Kf6ytqqRoII_uddkzKyXCVx8YY3i$</a><br>
> To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
<br>
<br>
--<br>
Michael A. Grady<br>
IAM Architect, Unicon, Inc.<br>
<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!IBzWLUs!RoJN5TqJgxIqBjxs0ZTf5glsku1fHX05K56av_eI8jtYfx61kOu_Kf6ytqqRoII_uddkzKyXCVx8YY3i$" data-outlook-id="00f9f12a-8cb6-4986-bcb4-3aa582f0a5ae">
https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!IBzWLUs!RoJN5TqJgxIqBjxs0ZTf5glsku1fHX05K56av_eI8jtYfx61kOu_Kf6ytqqRoII_uddkzKyXCVx8YY3i$</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</div>
</div>
</body>
</html>