Office 365 App Registration Strange issue on Mac

Lalith Jayaweera ljayaweera at gmail.com
Thu Aug 3 18:35:44 EDT 2017


Hi Scot

Thanks for the reply,

If we change this SP to use Password flow, they will be presented with the
IDP login screen, not CAS login screen hence it is not SSO and user
experience will be different.

All the SPs are via CAS except ECP flow for Microsoft, which means, when
they login to our Portal via CAS, they can click any SP link which will
seamlessly go the SP landing page (because user has already logged in via
CAS).

If I only change one SP to go thru Password flow, they will be presented
with a another login screen as the flow is not Shibcas hence having a
different user experience.

So my question is, given this is only happening in Mac, at least to narrow
down the issue, within the relying party, is there any way to
detect whether request from Mac etc (possibly via userAgent or by
othermeans) and direct to the Password Flow, I don't think any need of SSO
for this particular function where all happening inside a embedded window.

Let me know or any other way to approach this.

As a side note, I am going to query(raise an incident) Microsoft about this
particular behavior happening inside Embedded UI view, however I might not
have a answer if they ask, what exactly the cookies you think missing etc.

Thanks




On Thu, Aug 3, 2017 at 11:38 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 8/3/17, 1:01 AM, "users on behalf of Lalith Jayaweera" <
> users-bounces at shibboleth.net on behalf of ljayaweera at gmail.com> wrote:
>
> > it appears the two re-directions happening form IdP to CAS and CAS to
> IdP, something getting missed in between
>
> Yes, by the client, it's probably mangling parameters, cookies, redirects,
> or all of the above. If you want to know what it's doing, exactly, you are
> the only one in a position to determine that.
>
> > So is there any way to detect (by some means) this flow and have a
> different relying Party or any other suggestion, basically no
> > issues providing Password flow for this interaction as well.
>
> You can certainly direct it to use the Password flow for just a single SP
> and leave all the others alone.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170804/d2632fa2/attachment-0001.html>


More information about the users mailing list