Office365 and Shibboleth 3 idp SSO

Walter Forbes Hoehn (wassa) wassa at memphis.edu
Mon Oct 3 09:34:08 EDT 2016


First, let me qualify everything that follows by making it clear that I can’t speak authoritatively on this topic. It’s been about a year since I tested this integration, and at the time I found the available documentation to be confusing, at best.

My experience, however, was that I had to use “urn:oasis:names:tc:SAML:2.0:named-format:persistent” to get it working. Instead of defining a new format, MS overloaded this format definition to carry its “ImmutableId.” The further complication is that the ImmutableId can be defined differently, depending on your Office365 configuration. I believe the default is to use the objectGuid from AD.

-WFH


> On Oct 3, 2016, at 8:08 AM, Priyanshu Bhalotia <priyanshu.bhalotia at wooqer.com> wrote:
> 
> Hi guys,
> so i have integrated my SSO with Office365 using Shibboleth3 idp but i
> have used nameid-format: persistent to configure the ImmutableID
> required by Microsoft to authenticate the user in my  saml-nameid.xml
> file during my setup.
> 
> I wanted to know whether it can be done with
> "nameid-format:unspecified" to setup the integration.
> if yes, any lead would be appreciated!
> 
> -- 
> Priyanshu Bhalotia
> Platform Engineer
> Wooqer
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list