Functionality
- Always enable the MFA Admin application (for lockout- and token management) and assign it to the local http interface (for protection).
- When signing is used (for tickets etc), upload a specific certificate. Do not use the certificate shipped with the product.
- Configure SLO from the beginning for federation/oidc flows.
- Change the redirect for / (defaults to /config). Change from /config to something relevant at the customer.