<div dir="ltr">Thanks again Scott. Your insights and assistance is greatly appreciated.</div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Sep 25, 2015 at 10:30 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 9/25/15, 1:05 PM, "users on behalf of Cathy Scott" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:cathystill@gmail.com">cathystill@gmail.com</a>> wrote:<br>
<br>
>Yes, changing the decoder back to ScopedAttributeDecoder resolved the issue. This is a dedicated environment and will never have any other IdP authenticating in the environment. I do want to employ best practice.<br>
<br>
</span>The best practice is to stick to standardized attribute (not EPPN necessarily, but there are in fact no standard identifier attributes in the world except for the ones we defined). But that would imply not creating mappings in the SP for any proprietary attributes from ADFS.<br>
<br>
Since you did that, you're basically creating work on both ends. You added the mappings, and they apparently mapped the claim name into an EPPN. I'm saying pick one option, basically. Either they send standard stuff, or you map non-standard stuff.<br>
<br>
Also, the better practice is not to just delete the scope checking. You can alter the metadata supplied by ADFS that you load to add in the Scope extension that authorizes the scoped values. That assumes the metadata isn't coming from a federation that's already curating the metadata and already provides the Scope extension, which is the actual best practice.<br>
<span><br>
> May I ask what the risk is and why you would not make these changes? Is there a better way to integrate with ADFS IdP?<br>
<br>
</span>Doing things incorrectly or confusingly creates a mess for somebody else to cleanup when they inevitably inherit an pile of unexplained settings and then have to go ask for help.<br>
<br>
I don't really understand any of the changes made or why they were made.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>