ACR requirements for inbound SSO and portal implementation changes

Last update:
Aug 21, 2026
In the past, Inbound SSO did not require any authentication and let the users access HSID applications. However, due to the UHG security policy changes, Inbound SSO users also need to go through Risk Based Authentication and possible MFA, depending on the user’s risk score and what level of authentication is done on External Vendor, which is passed as ACR in the SAML. For the details, please refer to this document.
With this new requirement, the following changes are required:
  • 1-hop SSO
    External vendor needs to pass ACR to PingFederate.
  • 2-hop / 2-key SSO:
    • External Vendor needs to pass ACR to PingFederate.
    • PingFederate passes authn_cntx attribute to Portal, in addition to the user attributes.
    • Portal needs to pass back authn_cntx attribute to PingFederate (pass-through), in addition to the user attributes (Either Agentless or Opentoken manner, see the next section)

On this page

Powered by Aikyam @2025 All rights reserved