Educause Security Discussion mailing list archives

Re: Social Login/MFA


From: Jeremy Rosenberg <rosey () BERKELEY EDU>
Date: Sat, 22 Sep 2018 14:15:14 -0400

We have discussed what it would look like and presuming they have MFA on
their social account, they would have to MFA twice. We didn’t investigate
whether the social login can assert whether a second factor was present
during the social login.  But if you need that level of assurance, perhaps
social logins isn’t the right solution for the first factor?

-- 
Jeremy Rosenberg
Chief Information Security Officer
UC Berkeley
510-990-5521

On September 21, 2018 at 12:28:11 PM, Razi Ahmad (razi.ahmad () stern nyu edu)
wrote:

Hi all,

Is anyone using Social Login for SSO AND enforcing MFA? We have a possible
use case at NYU Stern but have not done anything like this in the past and
are interested in finding out if any other institution has managed to
accomplish something like this.

Thanks,

Razi Ahmad
Associate Director, Enterprise Services
Information Technology
NYU Stern School of Business
212-998-0172
razi () stern nyu edu <razi.ahmad () stern nyu edu>

Current thread: