[EXTERNAL] Re: Using the IdP behind Entra?
Bobby Lawrence
robertl at jlab.org
Mon Jul 28 13:04:59 UTC 2025
Just an FYI - its entirely possible to configure Entra to delegate authentication to Shibboleth (so that Entra acts as a SAML proxy). We have our tenant configured exactly this way so that at our organization doesn't need to sync passwords to them in the cloud.
https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-fed-saml-idp
From: users <users-bounces at shibboleth.net> On Behalf Of Baron Fujimoto via users
Sent: Thursday, July 24, 2025 8:46 PM
To: Cantor, Scott <cantor.2 at osu.edu>
Cc: Baron Fujimoto <baron at hawaii.edu>; Shib Users <users at shibboleth.net>
Subject: [EXTERNAL] Re: Using the IdP behind Entra?
It's entirely possible I've reversed the directional terminology; I was thinking of it from the user's perspective where they would have Entra as the login UX, but the SPs and applications are still interacting with the IdP. Would this be proxying the authentication from the IdP's perspective?
Thank you for the confirmation on the references as well as the pointers to the Microsoft and IdP KB references. I'll take a closer look now that I know that's the path forward. Hopefully I can begin to connect the dots and flesh things out between the general SAML Authn Configuration page and the specific IdPv5 KB example for Entra. Hopefully in the process it will become clearer how this applies to the CAS aspects. I'm sure I'll have more questions when I know more about what I don't know and can ask more intelligent questions about it.
But thank you for at least providing us for now with a baseline confidence that we can proceed with our CAS protocol unification efforts and that we have a viable path forward with this.
On Thu, Jul 24, 2025 at 11:35 AM Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
I kind if suspect you're reversing the normal directonal terminology.
Putting Entra "in front" would mean integrating applications against Entra and authenticating users to Entra with Shiibboleth and I imagine that's perhaps not possible. Entra probably can't delegate to another SAML IdP. I could be wrong.
Proxying authentication of Shibboleth to Entra is very trivial. The docs for that are the ones you found. The KB articles are a supplement, there's one for V4 and one for V5, but they are not the primary source.
The IdP can proxy authentication to anything else but still issue CAS tickets or SAML assertions out without any problems.
-- Scott
--
Baron Fujimoto <baron at hawaii.edu<mailto:baron at hawaii.edu>> ::: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum descendus pantorum
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250728/293354ae/attachment.htm>
More information about the users
mailing list