Using the IdP behind Entra?

Steven Premeau steven.premeau at maine.edu
Thu Jul 24 20:56:28 UTC 2025


Baron -

  There are a couple of known ways to handle this, depending on the details
of your architecture.

  How the Shibboleth IDP authenticates account holders is (mostly)
independent of how it responds to the authentication request from service
providers.  (The caveat is if you'd like to use Entra for attributes... )

  The following URLs may help:

https://learn.microsoft.com/en-us/entra/architecture/multilateral-federation-solution-two

https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1467056889/Using+SAML+Proxying+in+the+V4+Shibboleth+IdP+to+connect+with+Azure+AD

(This is a V4 document, but it should apply to V5 without too much
difficulty.)

Steve.

On Thu, Jul 24, 2025 at 4:43 PM Baron Fujimoto via users <
users at shibboleth.net> wrote:

> We've recently learned that we will be adopting Entra as for
> authentication and SSO institution-wide. We currently use both Apereo CAS
> and the Shibboleth IdP to provide SSO. We actually currently use CAS for
> authn for our IdP as well, so we can present a single unified UX to our
> users, but we were in the process of consolidating these services into a
> unified Shibboleth IdP service for both CAS, SAML, and other protocols as
> needed. Needless to say, this has thrown quite the wrench into our work.
>
> We will still need to support both the SAML and CAS protocols, because we
> have many SPs and applications already integrated with them for SSO. It is
> our understanding that Entra supports neither SAML nor CAS, so we will have
> to have some way to put Entra in front of them for the initial
> authentication, then pass on the results for the rest of the workflow to
> the backend IdP service to handle these protocols. (I'm not sure what the
> term of art would be for this, "authentication proxy" or something similar?)
>
> Our initial research suggests that putting Entra in front of the
> Shibboleth IdP is something that's generally possible (at least for SAML?),
> but I couldn't find anything that went into much detail. We would greatly
> appreciate any pointers or tips on where to start, or even good questions
> we should be asking about this. One big question that comes up immediately
> for us, is assuming we can use the IdP for the SAML stuff, does it also
> work when the IdP is handling CAS as well? The answer to this would
> determine whether we should even continue with our attempts to bring CAS
> under the aegis of the IdP, or whether we need to maintain a separate
> Apereo CAS for this.
>
> FWIW, I did find the following in the IdP wiki:
>
> - includes a note about "Intra" [sic]
>   <
> https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration
> >>
>
> - CAS Proxy info, deprecated, references ProxyValidator, but can't find
> add'l info
>   <
> https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199506501/CASProxyAuthenticatorDeprecation
> >
>
> --
> Baron Fujimoto <baron at hawaii.edu> ::: UH Information Technology Services
> minutas cantorum, minutas balorum, minutas carboratum descendus pantorum
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250724/ccf71a31/attachment.htm>


More information about the users mailing list