Setting domain hint/auto-acceleration for IdP proxied behind Entra

Mark Cairney Mark.Cairney at ed.ac.uk
Thu Nov 14 17:02:35 UTC 2024


Hi,

In order to get MFA support we've started the journey of migrating our 
IdPs from sitting behind our legacy authentication system (Cosign) to 
being proxied behind Entra using the

new SAML proxying functionality.

I've got to the point after following the guide where I can successfully 
log into a SP using our Test IdP and it issues the same attributes to 
the SP as it did previously. However the redirect out to Entra takes the 
client out to the main Microsoft 365 login page where they then have to 
enter their email address/username to be guided to our Entra login page. 
To simplify the login experience and reduce the opportunity for user 
error it would be good if this could go straight to our organisational 
landing page bypassing the central Microsoft HRD portal (a process 
Microsoft calls 'auto-acceleration').

Having done a bit of reading up e.g. on 
https://learn.microsoft.com/en-us/answers/questions/855476/domain-hint-alternative-for-saml 
it appears that this can be done by setting a policy within Azure itself 
and assigning it to the Shibboleth IdP's Enterprise Application or by  
setting the domain hint.


Is there any way of setting this at the IdP level? So far the best I've 
come up with is appending the query string to the endpoint URLs in the 
metadata file for the upstream Azure IdP but this seems a bit hacky and 
isn't going to work if you're downloading the metadata.

What are other SAML proxy setups doing in this regards (if anything?)

Kind regards,

Mark


-- 
/****************************

Mark Cairney
ITI Enterprise Services
Information Services
University of Edinburgh

Tel: 0131 650 6565
Email: Mark.Cairney at ed.ac.uk

*******************************/

The University of Edinburgh is a charitable body, registered in Scotland, with registration number SC005336.



More information about the users mailing list