<div dir="ltr">Just to close the loop, we were able to make this work. I added some notes to the wiki <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop#MicrosoftInterop-AccessControlService">here</a>.</div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Dec 14, 2015 at 10:41 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 12/14/15, 6:29 AM, "users on behalf of Robert Lowe" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:robertmlowe@rmlowe.com">robertmlowe@rmlowe.com</a>> wrote:<br>
<br>
<br>
<br>
>* The SP clearly supports<br>
>WS-Federation <<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPADFS" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPADFS</a>> in some form<br>
<br>
It supports the WSF passive profile for SSO using SAML 1.1 assertions. That's it.<br>
<span class=""><br>
>, however this seems to be specifically targeted at ADFSv1<br>
<br>
</span>Has nothing to do with ADFSv1 specifically, it's an old profile supported by a number of products but mostly irrelevant now.<br>
<span class=""><br>
>, so it's not clear whether this would be sufficient to talk to Access Control Service.<br>
<br>
</span>That's a question for Microsoft.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr">Best regards,<br><br>Robert Lowe<br><a href="http://crepuscular.rmlowe.com/" target="_blank">http://crepuscular.rmlowe.com/</a></div></div>
</div>