<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); ">
<div style="font-family: Calibri, sans-serif; font-size: 14px; ">If you are <span style="font-style: italic; ">
replacing</span>&nbsp;your Shib IdP with ADFS as the IdP and answering SAML requests, maybe, but I could see a lot of heartache managing metadata within ADFS and doing claims mapping.</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; ">See adfstoolkit.org for more in this vein and related comments from Scott a few moments ago.</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; "><br>
</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; ">It's plausible(and debatable) &nbsp;to have Shibboleth as the IdP on IIS and defer to ADFS for sign on (like Shibboleth can do with CAS)&nbsp;but the Shibboleth software would need more than just a token,
 it would need the unique identifier to look up the user in Shibboleth to be able to handle other Shibboleth protected services and Office 365 would just use ADFS.&nbsp;</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; "><br>
</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; ">If you wanted to transition away from CAS to this, it's possible &#8212; at the expense of any CAS'ified apps will need to be converted to SAML or ADFS.</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; "><br>
</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; ">I would encourage you to have the consultant diagram it out his/her recommendations in detail with the sign on use cases exercised with it.</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; "><br>
</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; ">You could always use the SAML capabilities of Office365[1] and skip ADFS entirely, but I suspect that Lync and Office Subscriptions may not work as expected(well, likely not at all in which case
 you would need ADFS)</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; "><br>
</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; ">Chris.</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; "><br>
</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; ">[1]&nbsp;<span class="Apple-style-span" style="font-size: 13px; font-family: Arial, sans-serif; "><a href="http://blogs.office.com/2014/03/06/announcing-support-for-saml-2-0-federation-with-office-365" target="_blank" style="color: blue; text-decoration: underline; ">http://blogs.office.com/2014/03/06/announcing-support-for-saml-2-0-federation-with-office-365</a></span></div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; "><br>
</div>
<span id="OLK_SRC_BODY_SECTION" style="font-size: 14px; font-family: Calibri, sans-serif; ">
<div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span>&lt;Qian&gt;, Yi &lt;<a href="mailto:yqian@ku.edu">yqian@ku.edu</a>&gt;<br>
<span style="font-weight:bold">Reply-To: </span>Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
<span style="font-weight:bold">Date: </span>Thursday, 3 April, 2014 10:30 AM<br>
<span style="font-weight:bold">To: </span>Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
<span style="font-weight:bold">Subject: </span>ADFS Shibboleth question<br>
</div>
<div><br>
</div>
<div>
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>Hello,</div>
<div><br>
</div>
<div>The University of Kansas using Shibboleth IdP to authenticate our users, now we are adding ADFS as IdP to authenticate user for o365, the consultant from MS told us that after ADFS success authentication, shib IdP can obtain the token issued by ADFS, so
 user does not require login to shib protected resources.</div>
<div><br>
</div>
<div>I think this must be some piece missing, should there is something like SP or some type replying party sit in front of shib IdP to intercept this token? But I do not know how</div>
<div><br>
</div>
<div>Thanks for the help</div>
<div><br>
</div>
<div>Yi</div>
</div>
</div>
</span>
</body>
</html>