<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>Hello,</div>
<div><br>
</div>
<div>The University of Kansas using Shibboleth IdP to authenticate our users, now we are adding ADFS as IdP to authenticate user for o365, the consultant from MS told us that after ADFS success authentication, shib IdP can obtain the token issued by ADFS, so
user does not require login to shib protected resources.</div>
<div><br>
</div>
<div>I think this must be some piece missing, should there is something like SP or some type replying party sit in front of shib IdP to intercept this token? But I do not know how</div>
<div><br>
</div>
<div>Thanks for the help</div>
<div><br>
</div>
<div>Yi</div>
</body>
</html>