Setting domain hint/auto-acceleration for IdP proxied behind Entra
Mark Cairney
Mark.Cairney at ed.ac.uk
Thu Nov 14 17:02:35 UTC 2024
Hi,
In order to get MFA support we've started the journey of migrating our
IdPs from sitting behind our legacy authentication system (Cosign) to
being proxied behind Entra using the
new SAML proxying functionality.
I've got to the point after following the guide where I can successfully
log into a SP using our Test IdP and it issues the same attributes to
the SP as it did previously. However the redirect out to Entra takes the
client out to the main Microsoft 365 login page where they then have to
enter their email address/username to be guided to our Entra login page.
To simplify the login experience and reduce the opportunity for user
error it would be good if this could go straight to our organisational
landing page bypassing the central Microsoft HRD portal (a process
Microsoft calls 'auto-acceleration').
Having done a bit of reading up e.g. on
https://learn.microsoft.com/en-us/answers/questions/855476/domain-hint-alternative-for-saml
it appears that this can be done by setting a policy within Azure itself
and assigning it to the Shibboleth IdP's Enterprise Application or by
setting the domain hint.
Is there any way of setting this at the IdP level? So far the best I've
come up with is appending the query string to the endpoint URLs in the
metadata file for the upstream Azure IdP but this seems a bit hacky and
isn't going to work if you're downloading the metadata.
What are other SAML proxy setups doing in this regards (if anything?)
Kind regards,
Mark
--
/****************************
Mark Cairney
ITI Enterprise Services
Information Services
University of Edinburgh
Tel: 0131 650 6565
Email: Mark.Cairney at ed.ac.uk
*******************************/
The University of Edinburgh is a charitable body, registered in Scotland, with registration number SC005336.
More information about the users
mailing list