Releasing attributes from Active Directory for Office 365

Kevin P. Foote kpfoote at iup.edu
Tue Aug 27 10:10:19 EDT 2013


On Tue, 27 Aug 2013, Dennis Casimiro wrote:

> I can't seem to figure out or troubleshoot properly how to encode and
> pass attributes to MicrosoftOnline.
>
>
>
> The WARN error that appears applicable is:
>
>
>
> 08:47:10.342 - WARN
> [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHand
> ler:491] - No attribute of principal 'XXXXXX' can be encoded in to a
> NameIdentifier of required format
> 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent' for relying party
> 'urn:federation:MicrosoftOnline'

So with the IdP you can encode any of your resolved attributes into
particular formats for release as the NameId element.

My huntch is you are not encoding anything you are releasing to o365 into
the proper NameID format..

So take a look at your release for your o365 RP and then look at what
you have encoded into the format that the o365 RP wants. (hope that made
sense)

<https://wiki.shibboleth.net/confluence/display/SHIB2/NameIDAttributes>

HTH

------
thanks
  kevin.foote


More information about the users mailing list