This FAQ supports the use of the REFEDS Multifactor Authentication Profile. This documentation is intended to be non-normative supporting information. If you have any questions about the use of the REFEDS MFA Profile or this FAQ, please direct them to the REFEDS mailing list (refeds@lists.refeds.org).
Introducing the REFEDS MFA Profile
Learn the basics of the REFEDS MFA Profile, what it is, and how to use it.
Guidance for Identity Provider/OpenID Provider Operators
Explores tips for IdP Operator when supporting the REFEDS MFA Profile.
Guidance for Service Provider/Relying Party Operators
Discover how to use the REFEDS MFA Profile to request MFA, and how to handle responses from an Identity Provider.
Dealing with Institution MFA Policies
Does your institution's policies for handling MFA behavior conflict with external federated access requirements? Find out how to work through them.
Product specific questions
Get help with implementing REFEDS MFA Profile with popular IAM products.
How to use this FAQ
The REFEDS Multi-factor Authentication (MFA) Profile offers a succinct way for a service provider (SP/RP) to request MFA and for an Identity Provider (IdP/OP) to respond in an authentication transaction.
As more questions arise, we will add to this guide. Come back and visit regularly to get the latest information.
Terms/Abbreviations used in this FAQ
This FAQ references several acronyms and shortened terms. The following table provides keys to those abbreviations.
Term | Definition |
MFA | Multi-Factor Authentication |
REFEDS | The Research and Education FEDerations group (more info: https://refeds.org) |
Profile | REFEDS Multi-factor Authentication Profile; REFEDS MFA Profile |
SAML | Security Assertion Markup Language |
SP | A SAML Service Provider |
IdP | A SAML Identity Provider |
SSO | Single Sign-On |