Skip to content

Force Provider on the User without the option for the User to change it or use another Provider #228

Closed Answered by redhook62
TerrierX asked this question in Q&A
Discussion options

You must be logged in to vote

as you can imagine, we will not do any user management in this component,
we believe that this is only a matter of the "Access Control Policies" of ADFS.

However, we eventually add a (global) option forcing the user to take the default method that will be assigned to him (totp, Bio, mail), without being able to change it at runtime.

Then, sending the QRCode by email does not guarantee that the user has an email, on the other hand this email is an emergency method, it is above all not secure.
If you use PowerShell to provision your users, then specify the -SendKey flag

Replies: 2 comments 12 replies

Comment options

You must be logged in to vote
6 replies
@TerrierX
Comment options

@redhook62
Comment options

@TerrierX
Comment options

@redhook62
Comment options

@TerrierX
Comment options

Answer selected by TerrierX
Comment options

You must be logged in to vote
6 replies
@redhook62
Comment options

@TerrierX
Comment options

@redhook62
Comment options

@redhook62
Comment options

@redhook62
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants