Re: MS Autopilot with Shibboleth

paras pandey paraspandey16 at rediffmail.com
Thu Oct 31 10:22:50 UTC 2024


Please unsubscribe me from this.
From: users at shibboleth.net
Sent: Thu, 31 Oct 2024 00:07:27 
To: Shib Users <users at shibboleth.net>
Cc: Youssef  GHORBAL <youssef.ghorbal at pasteur.fr>
Subject: Re: MS Autopilot with Shibboleth





 

Hi,



Autopilot in Entra federation scenarios requires the IdP to support WS-Trust[0] which Shibboleth does not. 
Your options are:
- AD Hash sync, where your AD acounts and passwords hashes are synced to EntraID and you don't federate your o365 tenant. In that case users use standard Microsoft auth screens and not your institutional
 portal for *ALL* o365 based apps (Teams, office.com, etc)
- EntraID federation with an IdP that supports WS-Trust. The only one I'm aware of that you can roll inhouse is ADFS. The rest of viable options are Cloud based basically (Okta, Duo, etc)

In the ADFS scenario, I'm not sure how much WS-Trust endpoints that you'll end up exposing on Internet are immune against brute force (my WS-* is rusty) so you may also look into protection strategies[1]



>From my understanting, this "requirement" for WS-Trust boils down to the fact that in federated EntraID scenarios MS does not have your password and at some point in the enrollement process, you'll
 be prompted to authenticate with corp credentials that needs to be checked (agains your IdP) without a browser/user interaction, more details here[2]. So I guess they ended digging up WS-Trust.



By the way in macOS env, you'll need WS-Trust as well for Platform SSO[3] for the same reasons I guess.



Last but not least, I don't know if you go down to alternative auth methods for Windows (hardware tokens or Windows Hello) you can workaround the WS-Trust requirement.



Youssef




[0] https://learn.microsoft.com/en-us/entra/identity/devices/device-join-plan#federated-environment

[1] https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-ad-fs-extranet-smart-lockout-protection

[2] https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token#prt-issuance-during-first-sign-in
[3] https://support.apple.com/en-gb/guide/deployment/dep7bbb05313/web





On 30 Oct 2024, at 16:04, Matt Brennan via users <users at shibboleth.net> wrote:


Hi Folks,



  Has anyone gotten MS Autopilot to work while federating Entra (formerly known as Azure AD) to Shibboleth? We're running into an issue right now where we get an error at the very first login screen which says the identity was not found in the directory. 



  Our implementation partner is telling us that this will never work because the IdP needs to support WS-Trust (referencing this article:

https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join). 



  All the posts I'm finding agree, but they're also all several years old. I just wanted to see if anyone had made this work recently -- either through Shibboleth, or by some hackery to let the user authenticate via Entra only for Autopilot. 



Thanks,
Matt

-- 

For Consortium Member technical support, see https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!JFdNOqOXpB6UZW0!v-xl4MeYNTrsIs0ZNnWRNLIR1aRUkpHm52wO91G2E2BS4eDUChxcHiSW0silm20uVRNOlE-jIr6BTvruVqRz9EYysw$


To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net







 
 
-- 

For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw

To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241031/9a537411/attachment.htm>


More information about the users mailing list