Using the IdP behind Entra?

Cantor, Scott cantor.2 at osu.edu
Thu Jul 24 21:35:39 UTC 2025


I kind if suspect you're reversing the normal directonal terminology.

Putting Entra "in front" would mean integrating applications against Entra and authenticating users to Entra with Shiibboleth and I imagine that's perhaps not possible. Entra probably can't delegate to another SAML IdP. I could be wrong.

Proxying authentication of Shibboleth to Entra is very trivial. The docs for that are the ones you found. The KB articles are a supplement, there's one for V4 and one for V5, but they are not the primary source.

The IdP can proxy authentication to anything else but still issue CAS tickets or SAML assertions out without any problems.

-- Scott




More information about the users mailing list