Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This FAQ supports the use of the REFEDS Multifactor Authentication Profile in SAML.  This documentation is intended to be non-normative supporting information.  If you have any questions about the use of the REFEDS MFA Profile, please direct them to the REFEDS mailing list (refeds@lists.refeds.org). 

Introducing the REFEDS MFA Profile

Learn the basics of the REFEDS MFA Profile, what it is, and how to use it.

Section


Column
width25%20%



Column


Panel
borderColor#999
borderWidth1
borderStylesolid

View Topics



Column
width25%



Guidance for Identity Provider Operators

Explores tips for IdP Operator when supporting the REFEDS MFA Profile.

Section


Column
width25%20%


Column


Panel
borderColor#999
borderWidth1
borderStylesolid

View Topics



Column
width25%


Guidance for Service Provider Operators

Discover how to use the REFEDS MFA Profile to request MFA, and how to handle responses from an Identity Provider.

Section


Column
width25%20%



Column


Panel
borderColor#999
borderWidth1
borderStylesolid

View Topics



Column
width25%



Dealing with Institution MFA Policies

Does your institution's policies for handling MFA behavior conflict with external federated access requirements?  Find out how to work through them.

Section


Column
width25%20%



Column


Panel
borderColor#999
borderWidth1
borderStylesolid

View Topics



Column
width25%



Product specific questions

Get help with implementing REFEDS MFA Profile with popular IAM products.

Section


Column
width25%20%



Column


Panel
borderColor#999
borderWidth1
borderStylesolid

IdP Product Topics


Panel
borderColor#999
borderWidth1
borderStylesolid

SP Product Topics



Column
width25%



Relationships to Other Standards

Uncover how Refeds MFA Profile relates to, supports, and is supported by other REFEDS and industry standards.

Section


Column
width25%20%


Column


Panel
borderColor#999
borderWidth1
borderStylesolid

View Topics



Column
width25%






How to use this FAQ

The REFEDS Multi-factor Authentication (MFA) Profile offers a succinct way for a service provider (SP) to request MFA and for an Identity Provider (IdP) to respond in a SAML authentication transaction. 

This guide explains the relationship between SAML and the REFEDS MFA Profile, provides implementation best practices, and clarifies ambiguities in the REFEDS MFA Profile. Use this guide as a complement to the formal specification documents to help you make the right choices when implementing the REFEDS MFA Profile. 

As more questions arise, we will add to this guide. Come back and visit regularly to get the latest information.

Terms/Abbreviations used in this FAQ

This FAQ references several acronyms and shortened terms. The following table provides keys to those abbreviations.

Term

Definition

MFA

Multi-Factor Authentication

REFEDS

The Research and Education FEDerations group (more info: https://refeds.org)

Profile

REFEDS Multi-factor Authentication Profile; REFEDS MFA Profile

SAML

Security Assertion Markup Language

SP

A SAML Service Provider

IdP

A SAML Identity Provider

SSO

Single Sign-On


Additional Links

REFEDS MFA Profile