# How to check ACR level to decide when step-up authentication is needed

**URL:** <https://forum.keycloak.org/t/how-to-check-acr-level-to-decide-when-step-up-authentication-is-needed/23346>\
**Category:** Miscellanaeous\
**Created:** [November 14, 2023, 8:49pm UTC](https://forum.keycloak.org/t/how-to-check-acr-level-to-decide-when-step-up-authentication-is-needed/23346 "2023-11-14T20:49:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbenn](https://avatars.discourse-cdn.com/v4/letter/b/c5a1d2/32.png) [@bbenn](https://forum.keycloak.org/u/bbenn)\
**Post date:** [November 14, 2023, 8:49pm UTC](https://forum.keycloak.org/t/how-to-check-acr-level-to-decide-when-step-up-authentication-is-needed/23346/1 "2023-11-14T20:49:29Z")

</div>

In our Keycloak setup, I would like to enforce MFA for clients using an external IdP to ensure our company meets certain security standards. However, some of our clients have an IdP that already uses MFA, and we would like to avoid pushing our own MFA solution on them if they have it enabled. How can I get Keycloak to check that they have step-up authentication setup in their external IdP, so that if they have it, I can skip our inhouse MFA, or make them authenticate with our MFA if they do not have it. Is there also a way for Keycloak to request ACR value when it communicates with the external IdP?

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [November 15, 2023, 7:15am UTC](https://forum.keycloak.org/t/how-to-check-acr-level-to-decide-when-step-up-authentication-is-needed/23346/2 "2023-11-15T07:15:18Z")

</div>

AFAIK you can’t really _request_ an ACR value to be returned. This depends on the external IdP if it supports ACR and if it maps the information to the token.

There’s the `amr` claim, which holds the information, how the user authenticated, but this is also not mandatory. Keycloak for example doesn’t map the information into the tokens by default, one would have to extend Keycloak and its authenticators to be able to handle this value.

> **[RFC 8176: Authentication Method Reference Values](https://datatracker.ietf.org/doc/html/rfc8176)**
>
> The "amr" (Authentication Methods References) claim is defined and registered in the IANA "JSON Web Token Claims" registry, but no standard Authentication Method Reference values are currently defined. This specification establishes a registry for...
