<html><head><style data-externalstyle="true">
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
}

p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst, p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle, p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
line-height:115%;
}
</style><style><!--
.EmailQuote {
padding-left:4pt;
margin-left:1pt;
border-left-color:rgb(128, 0, 0);
border-left-width:2px;
border-left-style:solid;
}
--></style></head><body><div data-externalstyle="false" style="font-family:Calibri,'Segoe UI',Meiryo,'Microsoft YaHei UI','Microsoft JhengHei UI','Malgun Gothic','Khmer UI','Nirmala UI',Tunga,'Lao UI',Ebrima,sans-serif;font-size:16px;"><div>Microsoft has published a whitepaper that provides details of many of the ways ADFS interacts with Office 365.&nbsp; You should review this to understand which features can only be handled with ADFS.</div><div data-focusfrompointer="true">&nbsp;</div><div data-focusfrompointer="true"><a tabindex="-1" href="http://www.microsoft.com/en-us/download/details.aspx?id=28971">http://www.microsoft.com/en-us/download/details.aspx?id=28971</a></div><div data-focusfrompointer="true"><br>Rather than ADFS or Shibboleth it is relatively easy to use both where Shibboleth handles authentication for the ADFS token service for browsers but ADFS&nbsp;handles the rich clients.</div><div>&nbsp;</div><div>Randy</div><div>&nbsp;</div>        <div style="border-top-color: rgb(225, 225, 225); border-top-width: 1px; border-top-style: solid;">                <strong>From:</strong>&nbsp;Sam Jones<br>                <strong>Sent:</strong>&nbsp;‎January‎ ‎21‎, ‎2013 ‎4‎:‎15‎ ‎AM<br>                <strong>To:</strong>&nbsp;users@shibboleth.net<br>                <strong>Subject:</strong>&nbsp;Shibboleth and Office 365<br>        </div>        <div>&nbsp;</div>




<font size="2"><span style="font-size: 10pt;"><div class=" PlainText">Hello,<br>
<br>
Currently here, we host student email on Live@EDU, and recently there has been talk about moving that to Office 365.<br>
<br>
We use the Live@EDU SSO toolkit to provide single-sign-on to users who have authenticated to CAS. CAS also fronts the Shibboleth IDP, so users who have authenticated to CAS also get single sign on to Shibboleth resources/services.<br>
<br>
With the approaching move to Office 365, we are discussing the relative merits of either using the Shibboleth IDP to authenticate users to Office 365, or to setup a separate ADFS infrastructure to handle this.<br>
<br>
We've done a certain amount of technical work to try and integrate our dev IDP with a test domain in Office 365 to prove the concept and are relatively happy with it at that level.<br>
<br>
However, something I am often asked, but am unable to answer, is what other institutions authenticate their users to Office365 via Shibboleth. Therefore, I wonder if people on this list could tell me about their experiences of using Shib to authenticate to O365 in production? I'd also be interesting in hearing from anyone who hasn't yet implemented, but intends to do this in production.<br>
<br>
All the best,<br>
<br>
Sam Jones.<br>
--<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div></span></font>


</div></body></html>