This FAQ supports the use of the REFEDS Multifactor Authentication Profile. This documentation is intended to be non-normative supporting information. If you have any questions about the use of the REFEDS MFA Profile or this FAQ, please direct them to the REFEDS mailing list (refeds@lists.refeds.org).
Learn the basics of the REFEDS MFA Profile, what it is, and how to use it.
Explores tips for IdP Operator when supporting the REFEDS MFA Profile.
Discover how to use the REFEDS MFA Profile to request MFA, and how to handle responses from an Identity Provider.
Does your institution's policies for handling MFA behavior conflict with external federated access requirements? Find out how to work through them.
Get help with implementing REFEDS MFA Profile with popular IAM products.
The REFEDS Multi-factor Authentication (MFA) Profile offers a succinct way for a service provider (SP/RP) to request MFA and for an Identity Provider (IdP/OP) to respond in an authentication transaction.
As more questions arise, we will add to this guide. Come back and visit regularly to get the latest information.
This FAQ references several acronyms and shortened terms. The following table provides keys to those abbreviations.
Term | Definition |
MFA | Multi-Factor Authentication |
REFEDS | The Research and Education FEDerations group (more info: https://refeds.org) |
Profile | REFEDS Multi-factor Authentication Profile; REFEDS MFA Profile |
SAML | Security Assertion Markup Language |
SP | A SAML Service Provider |
IdP | A SAML Identity Provider |
SSO | Single Sign-On |