MS Autopilot with Shibboleth
Muhammad Farhan SJAUGI
farhan at sifulan.my
Wed Oct 30 16:35:09 UTC 2024
Hi Matt,
Well, you still need an AD server to make ADFS work. However, you
don't have to have full blown user entries there. Yes, you are right
the ADFS handle the WS-Fed, while Shibboleth handle the SAML authn.
Between ADFS and Shibboleth we use SAML. In our case we configured
EntraID as a Relying Party Trusts and Shibboleth IdP as a Claims
Provider Trusts. We tested using Shibboleth and SAML directly to Entra
ID before; while it worked for office.com, but not for Entra Join.
However, we don't know yet if this setup would have a significant
negative effect in the future (finger crossed). Unfortunately, we
don't have much options.
Regards
--
Ts. Muhammad Farhan Sjaugi, S.Kom. M.Sc.
VP (Engineering and Services)
SIFULAN Malaysian Access Federation
Email: farhan at sifulan.my | Website: https://www.sifulan.my
PGP Fingerprint: 9AA0 1861 0921 3EBD 4E30 716A 1F71 FC55 49CD D06C
MBOT: GT20040131 | ORCID: https://orcid.org/0000-0001-8497-1768
Credly: https://www.credly.com/users/muhammad-farhan-sjaugi
On Thu, Oct 31, 2024 at 12:13 AM Matt Brennan <brennanma at gmail.com> wrote:
>
> Hi Muhammad,
>
> Thanks for the reply. I just want to make sure I understand you correctly. You deployed only the ADFS proxy -- you didn't actually need to build an ADFS cluster in your domain? So the proxy handled the WS-Federation requests, but Shib handled the SAML auth still? If that's correct, that certainly seems less daunting than running an AD FS cluster just to support Autopilot.
>
> -Matt
>
> On Wed, 30 Oct 2024 at 11:26, Muhammad Farhan SJAUGI <farhan at sifulan.my> wrote:
>>
>> Hi Matt,
>>
>> I haven't tested yet with MS Autopilot, but I managed to make
>> Shibboleth IdP work with the MS OOBE.
>>
>> What I did was, I put the ADFS (proxy) server in between Shibboleth
>> IdP and Entra ID, and used WS-Fed/WS-Trust to connect the ADFS and
>> EntraID.
>>
>> However, you may need to list some MS authentication context,
>> particularly http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password
>> in the Shibboleth IdP's supported AuthenticationContext.
>>
>> So far our method works well with Office365, Entra Join, and also OOBE.
>>
>> Regards
>>
>> --
>> Ts. Muhammad Farhan Sjaugi, S.Kom. M.Sc.
>> VP (Engineering and Services)
>> SIFULAN Malaysian Access Federation
>> Email: farhan at sifulan.my | Website: https://www.sifulan.my
>> PGP Fingerprint: 9AA0 1861 0921 3EBD 4E30 716A 1F71 FC55 49CD D06C
>> MBOT: GT20040131 | ORCID: https://orcid.org/0000-0001-8497-1768
>> Credly: https://www.credly.com/users/muhammad-farhan-sjaugi
>>
>> On Wed, Oct 30, 2024 at 11:05 PM Matt Brennan via users
>> <users at shibboleth.net> wrote:
>> >
>> > Hi Folks,
>> >
>> > Has anyone gotten MS Autopilot to work while federating Entra (formerly known as Azure AD) to Shibboleth? We're running into an issue right now where we get an error at the very first login screen which says the identity was not found in the directory.
>> >
>> > Our implementation partner is telling us that this will never work because the IdP needs to support WS-Trust (referencing this article: https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join).
>> >
>> > All the posts I'm finding agree, but they're also all several years old. I just wanted to see if anyone had made this work recently -- either through Shibboleth, or by some hackery to let the user authenticate via Entra only for Autopilot.
>> >
>> > Thanks,
>> > Matt
>> > --
>> > For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
>> > To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list