This FAQ supports the use of the REFEDS Multifactor Authentication Profile. This documentation is intended to be non-normative supporting information.  If you have any questions about the use of the REFEDS MFA Profile or this FAQ, please direct them to the REFEDS mailing list ( 

Introducing the REFEDS MFA Profile

Learn the basics of the REFEDS MFA Profile, what it is, and how to use it.

Guidance for Identity Provider/OpenID Provider Operators

Explores tips for IdP Operator when supporting the REFEDS MFA Profile.

Guidance for Service Provider/Relying Party Operators

Discover how to use the REFEDS MFA Profile to request MFA, and how to handle responses from an Identity Provider.

Dealing with Institution MFA Policies

Does your institution's policies for handling MFA behavior conflict with external federated access requirements?  Find out how to work through them.

Product specific questions

Get help with implementing REFEDS MFA Profile with popular IAM products.

How to use this FAQ

The REFEDS Multi-factor Authentication (MFA) Profile offers a succinct way for a service provider (SP/RP) to request MFA and for an Identity Provider (IdP/OP) to respond in an authentication transaction. 

As more questions arise, we will add to this guide. Come back and visit regularly to get the latest information.

Terms/Abbreviations used in this FAQ

This FAQ references several acronyms and shortened terms. The following table provides keys to those abbreviations.




Multi-Factor Authentication


The Research and Education FEDerations group (more info:


REFEDS Multi-factor Authentication Profile; REFEDS MFA Profile


Security Assertion Markup Language


A SAML Service Provider


A SAML Identity Provider


Single Sign-On

Additional Links


  • No labels