Using the IdP behind Entra?
Baron Fujimoto
baron at hawaii.edu
Fri Jul 25 00:46:23 UTC 2025
It's entirely possible I've reversed the directional terminology; I was
thinking of it from the user's perspective where they would have Entra as
the login UX, but the SPs and applications are still interacting with the
IdP. Would this be proxying the authentication from the IdP's perspective?
Thank you for the confirmation on the references as well as the pointers to
the Microsoft and IdP KB references. I'll take a closer look now that I
know that's the path forward. Hopefully I can begin to connect the dots and
flesh things out between the general SAML Authn Configuration page and the
specific IdPv5 KB example for Entra. Hopefully in the process it will
become clearer how this applies to the CAS aspects. I'm sure I'll have more
questions when I know more about what I don't know and can ask more
intelligent questions about it.
But thank you for at least providing us for now with a baseline confidence
that we can proceed with our CAS protocol unification efforts and that we
have a viable path forward with this.
On Thu, Jul 24, 2025 at 11:35 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
> I kind if suspect you're reversing the normal directonal terminology.
>
> Putting Entra "in front" would mean integrating applications against Entra
> and authenticating users to Entra with Shiibboleth and I imagine that's
> perhaps not possible. Entra probably can't delegate to another SAML IdP. I
> could be wrong.
>
> Proxying authentication of Shibboleth to Entra is very trivial. The docs
> for that are the ones you found. The KB articles are a supplement, there's
> one for V4 and one for V5, but they are not the primary source.
>
> The IdP can proxy authentication to anything else but still issue CAS
> tickets or SAML assertions out without any problems.
>
> -- Scott
>
>
>
--
Baron Fujimoto <baron at hawaii.edu> ::: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum descendus pantorum
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250724/89c8eb79/attachment.htm>
More information about the users
mailing list