<div dir="ltr"><br><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">
<br>
</span>Inquiring into the patching practices of federated partners is one of those things that you probably don&#39;t want to do unless you&#39;re prepared for the answer. For example, say they were awful (hint, hint)...what would you do as a result? Whose functionality are you prepared to turn off and who&#39;s going to defend that decision to management?<br>
<br>
Just doesn&#39;t happen much, sad to say.</blockquote><div><br></div><div>Very good point. I guess it&#39;s just on my mind as I&#39;m putting together a proposal to patch the code behind a Shib IdP RemoteUser check to chain on to an ADFS IdP rather than throwing up a form that does an LDAP-bind against AD (all part of the joy of using Office365 for email, needing a WS-Trust based IdP for things like Lync, and various internal web apps that authenticate directly against the system RemoteUser chains too).<br><br></div><div>Phil<br></div></div></div></div>