Use multitenant AAD for SAML flow

YF Lai ccyflai at ust.hk
Fri Dec 2 01:14:44 UTC 2022


Hi Ward,

Discovery is the solution in the Shibboleth way to address your problem.   You can still proxy SAML request to a single AAD tenant but you need to incorporate all users of another AAD tenant as a B2B account in that tenant.   This is AAD way of solving your problem and our site was working like this.

Regards,
-YF

-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott via users
Sent: Friday, 2 December 2022 7:53 am
To: Ward Poelmans <wpoely86 at gmail.com>; Shib Users <users at shibboleth.net>
Cc: Cantor, Scott <cantor.2 at osu.edu>
Subject: Re: Use multitenant AAD for SAML flow

>    But in this sense, we want Shibboleth to act as SP for Microsoft AAD?

My comment was referring to the difference between this code and the Shibboleth SP, which is looser. It doesn't remember as much about the requests it issues to be able to cross check the response. That's a *bad* thing, that was my badly stated point.

>    Well, basically we want to use Microsoft AAD SAML services as a 
> WAYF.

That's a much clearer goal for me to address. And no, this isn't how you do that. Discovery in SAML is standardized and does not  involve making requests to an IdP, it requires a discovery redirect  that returns the IdP to use back into the SP, and the proxy support does allow for that, it has properties for setting a discovery URL to use instead of just supplying the IdP to use.

>    But If I understand you correctly, it's not possible to do this. 
> The only solution is put a WAYF in front of it ourselves that 
> immediately redirect to the appropriate tenant?

Not exactly, discovery works by returning the IdP entityID to proxy to directly back to the proxy (the SP in this case, as you say). Otherwise, yes, that's basically the idea.

-- Scott


--
For Consortium Member technical support, see https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cccyflai%40ust.hk%7C20296fc1206743c36ff808dad3f74b89%7Cc917f3e2932249269bb3daca730413ca%7C1%7C0%7C638055356346756947%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=fBmERM5Wqqrs2hDH0GlcLz%2Fd7oCb7xIN2W1Em6csPdE%3D&reserved=0
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list