Shibboleth IDP for multiple trusted domains under one Office 365 tenant

solution79 solution79 at live.com
Thu Jun 6 20:37:53 EDT 2013


Hello Nate,

 

Let me put my question in form of an example:

 

Domains:

 

Abc.com

Xyz.com

 

Trusted on the Office 365 platform.

 

Using ADFS, user1 at abc.com <mailto:user1 at abc.com>   & user2 at xyz.com
<mailto:user2 at xyz.com>  can authenticate against ADFS.

But I am not sure if the same is possible with a single Shibboleth IDP?

 

Dematri

 

From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On
Behalf Of Nate Klingenstein
Sent: Friday, June 7, 2013 9:04 AM
To: Shib Users
Subject: Re: Shibboleth IDP for multiple trusted domains under one Office
365 tenant

 

Microsoft suggest that it can support multiple domains providing example of
ADFS that can support multiple domains part of a single tenant.
But based on the information I am getting on various forums Shibboleth
doesn't support multiple domains part of a single tenant.



 

Shibboleth can express most anything you want to express using SAML 2.0,
including an attribute that says "user A is in Office 365 domain B".  It can
even generate that information internally using a script.  It can't,
however, handle a custom protocol in a custom way to a particular service
provider out of the box.  See: DirSync.

 

It's good that they support this with ADFS, but I I would ask explicitly,
directly whether it's possible/how to express "user A, is in Office 365
domain B, which is part of tenant C" in SAML 2.0 form.  A nice answer would
be, "a scoped user ID, an attribute, and your entityID".

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130607/69e29191/attachment.html 


More information about the users mailing list