Federation - Communication of Authentication Event Time to RP, v1.0

Identity Providers must send RPs information about the last time the subscriber authenticated to the IdP when engaging in federated login, this is particularly important if the IdP supports long-term sessions.

Assessment Step

Authn Event Timing (AuthnEventTiming)
Does the IdP send information regarding the latest authentication event at the IdP to RPs? This is very critical when IdPs sessions are not expired for lengthy periods of time.
Provide evidence (e.g. policies, operational samples, screenshots) that the IdP sends information regarding the time of the latest authentication to RPs.

Conformance Criteria (1)

The IdP SHALL communicate any information it has regarding the time of the latest authentication event at the IdP,
NIST SP 800-63C
Section 5.3, Paragraph 1