<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;background-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p>I know a little bit about Office365, and a little bit about Shib. Does "had it working" mean that you successfully federated your Office365 tenant with your local Shibboleth IdP? No other things like ADFS being involved?</p>
<p><br>
</p>
<p>If so, does "had" mean that you ran the PowerShell commands to un-federate your tenant and have being using Office365's native authentication? If so, did that un-federate actually complete successfully? If it didn't, then you may be hitting an error trying
 to federate a tenant that thinks that it is already federated.</p>
<p><br>
</p>
<p>It's been a while, but I seem to recall that setting up the federation, using ADFS, had to be done from the primary ADFS server itself. I don't know how that would work if you're doing this with a Shib IdP instead of ADFS.<br>
</p>
<br>
<br>
<div style="color: rgb(0, 0, 0);">
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Paul Hethmon <paul.hethmon@clareitysecurity.com><br>
<b>Sent:</b> Wednesday, February 17, 2016 2:39 PM<br>
<b>To:</b> Shibboleth Users<br>
<b>Subject:</b> Re: off-topic help for Office 365</font>
<div> </div>
</div>
<div><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Feb 17, 2016, at 3:32 PM, Brent Putman <<a href="mailto:putmanb@georgetown.edu" class="">putmanb@georgetown.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div bgcolor="#FFFFFF" class="">
<blockquote type="cite" class="" style="font-family:Helvetica; font-size:14px; font-style:normal; font-variant:normal; font-weight:normal; letter-spacing:normal; orphans:auto; text-align:start; text-indent:0px; text-transform:none; white-space:normal; widows:auto; word-spacing:0px; background-color:rgb(255,255,255)">
<div class="">
<div class=""><br class="Apple-interchange-newline">
+ Set-MsolDomainAuthentication <<<<  -DomainName $dom -FederationBrandName $dom -Authentication Federated  -PassiveLogOnUri $url -SigningCertificate $cert -IssuerUri $uri -ActiveLogOnUri $ecpUrl -LogOffUri $logouturl -PreferredAuthenticationProtocol SAMLP</div>
<div class="">    + CategoryInfo          : OperationStopped: (:) [Set-MsolDomainAuthentication], MicrosoftOnlineException</div>
<div class="">    + FullyQualifiedErrorId : Microsoft.Online.Administration.Automation.InternalServiceException,Microsoft.Online.Administration.Automation.SetDomainAuthentication</div>
<div class=""><br class="">
</div>
</div>
<div class="">At this point, you supply MS support with useless information as they are apparently unable or unwilling to look into their own systems to find a real cause.<br class="">
</div>
<br class="">
</blockquote>
<br class="" style="font-family:Helvetica; font-size:14px; font-style:normal; font-variant:normal; font-weight:normal; letter-spacing:normal; orphans:auto; text-align:start; text-indent:0px; text-transform:none; white-space:normal; widows:auto; word-spacing:0px; background-color:rgb(255,255,255)">
<br class="" style="font-family:Helvetica; font-size:14px; font-style:normal; font-variant:normal; font-weight:normal; letter-spacing:normal; orphans:auto; text-align:start; text-indent:0px; text-transform:none; white-space:normal; widows:auto; word-spacing:0px; background-color:rgb(255,255,255)">
<span class="" style="font-family:Helvetica; font-size:14px; font-style:normal; font-variant:normal; font-weight:normal; letter-spacing:normal; orphans:auto; text-align:start; text-indent:0px; text-transform:none; white-space:normal; widows:auto; word-spacing:0px; background-color:rgb(255,255,255); float:none; display:inline!important">Yeah,
 nothing useful there. You have no access to any logs on the service side? Maybe they really do only support a CA-issued cert for some reason, who knows.  Or is there some sort of mismatch between the domain you are specifying in the call and the CN in the
 cert?  Otherwise I have no suggestions. <span class="Apple-converted-space"> </span></span><br class="" style="font-family:Helvetica; font-size:14px; font-style:normal; font-variant:normal; font-weight:normal; letter-spacing:normal; orphans:auto; text-align:start; text-indent:0px; text-transform:none; white-space:normal; widows:auto; word-spacing:0px; background-color:rgb(255,255,255)">
</div>
</div>
</blockquote>
</div>
<div class=""><br class="">
</div>
<div class="">I actually did have a mismatch on CN originally, but regenerated the cert to match them up.</div>
<div class=""><br class="">
</div>
<div class="">What kills me is that I had it working on a different IdP last fall, all I did is try to move it to a new IdP. Both using the same version of Shib (2.4) and both installed/created the same.</div>
<br class="">
<div class="">-----<br class="">
Paul Hethmon<br class="">
Chief Software Architect<br class="">
<a href="mailto:paul.hethmon@clareitysecurity.com" class="">paul.hethmon@clareitysecurity.com</a><br class="">
<br class="">
</div>
<br class="">
</div>
</div>
</div>
</body>
</html>