Shibboleth IDP for multiple trusted domains under one Office 365 tenant

Nate Klingenstein ndk at internet2.edu
Thu Jun 6 19:04:09 EDT 2013


Microsoft suggest that it can support multiple domains providing example of
ADFS that can support multiple domains part of a single tenant.
But based on the information I am getting on various forums Shibboleth
doesn't support multiple domains part of a single tenant.

Shibboleth can express most anything you want to express using SAML 2.0, including an attribute that says "user A is in Office 365 domain B".  It can even generate that information internally using a script.  It can't, however, handle a custom protocol in a custom way to a particular service provider out of the box.  See: DirSync.

It's good that they support this with ADFS, but I I would ask explicitly, directly whether it's possible/how to express "user A, is in Office 365 domain B, which is part of tenant C" in SAML 2.0 form.  A nice answer would be, "a scoped user ID, an attribute, and your entityID".
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130606/773d7700/attachment.html 


More information about the users mailing list