Using the IdP behind Entra?

Baron Fujimoto baron at hawaii.edu
Thu Jul 24 20:42:31 UTC 2025


We've recently learned that we will be adopting Entra as for authentication
and SSO institution-wide. We currently use both Apereo CAS and the
Shibboleth IdP to provide SSO. We actually currently use CAS for authn for
our IdP as well, so we can present a single unified UX to our users, but we
were in the process of consolidating these services into a unified
Shibboleth IdP service for both CAS, SAML, and other protocols as needed.
Needless to say, this has thrown quite the wrench into our work.

We will still need to support both the SAML and CAS protocols, because we
have many SPs and applications already integrated with them for SSO. It is
our understanding that Entra supports neither SAML nor CAS, so we will have
to have some way to put Entra in front of them for the initial
authentication, then pass on the results for the rest of the workflow to
the backend IdP service to handle these protocols. (I'm not sure what the
term of art would be for this, "authentication proxy" or something similar?)

Our initial research suggests that putting Entra in front of the Shibboleth
IdP is something that's generally possible (at least for SAML?), but I
couldn't find anything that went into much detail. We would greatly
appreciate any pointers or tips on where to start, or even good questions
we should be asking about this. One big question that comes up immediately
for us, is assuming we can use the IdP for the SAML stuff, does it also
work when the IdP is handling CAS as well? The answer to this would
determine whether we should even continue with our attempts to bring CAS
under the aegis of the IdP, or whether we need to maintain a separate
Apereo CAS for this.

FWIW, I did find the following in the IdP wiki:

- includes a note about "Intra" [sic]
  <
https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration
>>

- CAS Proxy info, deprecated, references ProxyValidator, but can't find
add'l info
  <
https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199506501/CASProxyAuthenticatorDeprecation
>

-- 
Baron Fujimoto <baron at hawaii.edu> ::: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum descendus pantorum
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250724/ac9c6929/attachment.htm>


More information about the users mailing list