<div dir="ltr"><div><div>I've got a scenario like this...</div><div><br></div><div>1. User accesses a protected resource</div><div>2. Shibboleth SP redirect to external IdP</div><div>3. login through external IdP gives <a href="mailto:username@email.com">username@email.com</a></div>
<div>4. Would it be possible to HERE make a lookup to Active Directory, search for the <a href="mailto:username@email.com">username@email.com</a> and retrieve the SAMAccountName together with the groups that the mailaddress (user) belongs to?</div>
<div><br></div><div>What would be the procedure or best practise to accomplish this? Would I need to also install Shibboleth IdP in order to make the lookup to the AD? The external IdP can't talk to the internal AD.</div>
<div><br></div><div>Maybe this should be designed in some other way? And maybe this is not how you do it at all. I'm grateful for any ideas or suggestions.</div><div><br></div><div>-- Rikard</div></div><div><br></div>
</div>