Claim containing URI references to the authentication methods utilised by the subject
Note: This attribute is never released to service providers, and direct use of it is not possible.
Attribute Definition
Friendly Name | http://schemas.microsoft.com/claims/authnmethodsreferences |
---|---|
OID | http://schemas.microsoft.com/claims/authnmethodsreferences |
Description | Claim containing URI references to the authentication methods utilised by the subject Note: This attribute is never released to service providers, and direct use of it is not possible. |
Format | Multi-valued, containing URI references |
References | |
Example |
|
Additional Notes | The http://schemas.microsoft.com/claims/authnmethodsreferences claim is only supported in the specific case of Microsoft AD FS and Azure AD identity providers; in all other circumstances it is filtered out. Where authnmethodsreferences includes a specific reference to the
REFEDS MFA profile of
It is also possible for the Federation hub to translate a
authnmethodsreferences claim asserting Microsoft’s multi-factor
authentication method ( Identity providers that wish to make use of REFEDS MFA and require this quirk must explicitly request it, and confirm that the multi-factor authentication methods they use are compatible with REFEDS MFA. For this quirk to work with AD FS, the IdP must assert at least one other authnmethodsreferences attribute value corresponding to the factor actually used. Some known-incompatible methods are automatically filtered (e.g. http://schemas.microsoft.com/ws/2012/12/authmethod/email), and only the remainder are considered. |