Un-scoped Microsoft IdPs and ePPN

Alan Buxey alan.buxey at myunidays.com
Wed Jan 21 18:19:13 UTC 2026


hi,

> We federate several of our SPs with other institutions, some of which use Microsoft Active Directory (on-prem or cloud) as their IdP. The Microsoft IdPs' metadata seem to universally lack the Scope attribute, asserting what domain(s) they are authoritative for. This means that shibboleth SP software will fail to accept eduPersonPrincipalName or any other scoped attribute from them, because they didn't assert a scope that includes the domain for the user.

as they are not in the federation , they are a 1:1 piece of work
anyway - so we insert the scope into the metadata - as there is no way
we'd be accepting unscoped values or allowing them to assert whatever
they want.  That's actually the easiest thing - the hardest thing is
to get them to configure attribute release that's suitable (ie a legal
ePPN value, or ePTID etc - likewise scoped affiliation.

alan


More information about the users mailing list