Shibboleth IDP for multiple trusted domains under one Office 365 tenant
solution79
solution79 at live.com
Thu Jun 6 20:37:53 EDT 2013
Hello Nate,
Let me put my question in form of an example:
Domains:
Abc.com
Xyz.com
Trusted on the Office 365 platform.
Using ADFS, user1 at abc.com <mailto:user1 at abc.com> & user2 at xyz.com
<mailto:user2 at xyz.com> can authenticate against ADFS.
But I am not sure if the same is possible with a single Shibboleth IDP?
Dematri
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On
Behalf Of Nate Klingenstein
Sent: Friday, June 7, 2013 9:04 AM
To: Shib Users
Subject: Re: Shibboleth IDP for multiple trusted domains under one Office
365 tenant
Microsoft suggest that it can support multiple domains providing example of
ADFS that can support multiple domains part of a single tenant.
But based on the information I am getting on various forums Shibboleth
doesn't support multiple domains part of a single tenant.
Shibboleth can express most anything you want to express using SAML 2.0,
including an attribute that says "user A is in Office 365 domain B". It can
even generate that information internally using a script. It can't,
however, handle a custom protocol in a custom way to a particular service
provider out of the box. See: DirSync.
It's good that they support this with ADFS, but I I would ask explicitly,
directly whether it's possible/how to express "user A, is in Office 365
domain B, which is part of tenant C" in SAML 2.0 form. A nice answer would
be, "a scoped user ID, an attribute, and your entityID".
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130607/69e29191/attachment.html
More information about the users
mailing list