<div dir="ltr">Hi list,<div><br></div><div>I see some old discussions around Access Control Service and whether it can be made to talk to the Shibboleth SP (such as <a href="http://shibboleth.net/pipermail/users/2014-February/014205.html">this one</a>), but no clear resolution, so thought I'd raise this again to see if there's any new information out there.</div><div><br></div><div>Here's what I've managed to figure out so far.</div><div><br></div><div><ul><li>Access Control Service is claimed to have “<a href="https://msdn.microsoft.com/en-us/library/azure/hh147631.aspx">support for SAML token formats</a>.” I take this to mean that it uses SAML assertions in some form, but doesn't support the full SSO profile.</li><li>In fact, it looks like Access Control Service can send SAML assertions inside WS-Federation messages.</li><li>The SP clearly supports <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPADFS">WS-Federation</a> in some form, however this seems to be specifically targeted at ADFSv1, so it's not clear whether this would be sufficient to talk to Access Control Service.</li></ul><div><br></div><div>Any insight welcomed. :-)</div><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr">Best regards,<br><br>Robert Lowe<br><a href="http://crepuscular.rmlowe.com/" target="_blank">http://crepuscular.rmlowe.com/</a></div></div>
</div></div>