<div dir="ltr"><div><div><div><div>Hi Rob,<br><br></div>Thanks for the information. You are right somewhere on o365 our old settings are stuck and thus I had issues at first instance which created all confusion.<br><br></div>
I am now able to authenticate at o365 and now the issue is signingout of the services. Thanks for the information you have provided.<br><br></div>Kind regards,<br><br></div>Farzan<br></div><div class="gmail_extra"><br><br>
<div class="gmail_quote">On 21 August 2014 06:07, Rob Gorrell <span dir="ltr"><<a href="mailto:rwgorrel@uncg.edu" target="_blank">rwgorrel@uncg.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><div class=""><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div>Secondly, about the link FederationMetaDataUrl. I understand that it has nothing to do (for this scenario at least) after the discussion had with Rob. May be my understanding was wrong. I thought that SP needs a metadata to process the flow and vice versa. But here, only our IdP needs metadata file.<br>
</div></div></blockquote><div><br></div></div><div>To be correct, the SP (O365) does need metadata, it just doesn't get it from a file or URL... but rather by you 'uploading' it using Powershell (Set-MsolDomainAuthentication cmdlet to be exact... the params you're supplying with this are in fact telling the SP about the IdPs metadata).<br>
<br><br></div><div>And yes, I agree with Scott's sentiments... I was struggling as well to understand how anything you did to the ADFS server mattered. If you configured the SP to use ADFS, those settings were likely still plugged into the domain, irregardless of you uninstalling/rebooting/doing whatever to the ADFS server. IdP and SP configurations happen separately, and my guess is you still had ADFS settings implanted into your O365 domain that was causing problems.<br>
<br></div></div>And just to be clear about what I mean and I'm no expert on the matter, but despite being both ways of "federating" with O365, there is little to no parity in how you configure ADFS vs SAML... and you will find many of the configuration options and powershell cmdlets that do this work aren't shared between the two approaches. This is what I meant when I cautioned you that unless otherwise specifically stated, Microsoft is assuming ADFS when talking about federating and that has no crossover to the SAML world. <br>
<span class="HOEnZb"><font color="#888888">
<br></font></span></div><span class="HOEnZb"><font color="#888888"><div class="gmail_extra">-Rob<br><br></div></font></span><div class=""><div class="gmail_extra"><br clear="all"><br>-- <br><div dir="ltr"><div>Robert W. Gorrell<br>
Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap"><a href="tel:336-334-5954" value="+13363345954" target="_blank">336-334-5954</a></span><br>PGP Key ID B36DB0CA<br></div></div>
</div></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><br>-- <br><font face="tahoma, sans-serif"><b>Farzan Qureshi</b> | Network Administrator & Help-desk Support | Rosmini College | (09) 487 0 530</font>
</div>
<br>
<font style="font-family:Verdana" size="1">This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager (<span style="font-weight:bold;font-style:italic"><a href="mailto:admin@rosmini.school.nz" target="_blank">admin@rosmini.school.nz</a></span>). Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the company. Finally, the recipient should check this email and any attachments for the presence of viruses. <span style="font-weight:bold">Rosmini College</span> accepts no liability for any damage caused by any virus transmitted by this email.</font>