Shibboleth IDP for multiple trusted domains under one Office 365 tenant
Nate Klingenstein
ndk at internet2.edu
Thu Jun 6 19:04:09 EDT 2013
Microsoft suggest that it can support multiple domains providing example of
ADFS that can support multiple domains part of a single tenant.
But based on the information I am getting on various forums Shibboleth
doesn't support multiple domains part of a single tenant.
Shibboleth can express most anything you want to express using SAML 2.0, including an attribute that says "user A is in Office 365 domain B". It can even generate that information internally using a script. It can't, however, handle a custom protocol in a custom way to a particular service provider out of the box. See: DirSync.
It's good that they support this with ADFS, but I I would ask explicitly, directly whether it's possible/how to express "user A, is in Office 365 domain B, which is part of tenant C" in SAML 2.0 form. A nice answer would be, "a scoped user ID, an attribute, and your entityID".
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130606/773d7700/attachment.html
More information about the users
mailing list