In the past, Inbound SSO did not require any authentication and let the users access HSID applications. However, due to the UHG security policy changes, Inbound SSO users also need to go through Risk Based Authentication and possible MFA, depending on the user’s risk score and what level of authentication is done on External Vendor, which is passed as ACR in the SAML. For the details, please refer to
this document.