<div dir="ltr">Hello all,<br><br>We are working on a scenario to federate our Microsoft Domain with the Microsoft Cloud using AD FS 3, but making AD FS to delegate passive authentication (web) to the Shiboleth IdP v3. The authentication flow should be:<br><br>1) Open <a href="http://portal.office.com">portal.office.com</a> (Office365) in a web browser and type an email address from our domain.<br>2) The Microsoft cloud redirects us to our AD FS server, which redirects us again to the Shibboleth IdP v3 login page.<br>3) When IdP v3 authenticates the user, it returns the control to AD FS, which sends the user validation to Office365.<br><br>We are stuck between points 2 and 3. The IdP succesfully authenticates the users from our Domain Controller (LDAP Connector), but something is wrong (we suppose) when sending the validation information back to AD FS. We have activated various DEBUG flags in Shibboleth, but it didn't help us so much to identify the problem.<br><br>We have searched A LOT for documentation about this deploying scenario, but no success. All the usefull information is for AD FS 2 and IdP v2, but no updated documentation for AD FS 3 and IdP v3. Do you know if this deploying scenario using both v3 is possible? Any updated documentation source to check?<br><br>Attached to this mail are the IdP log, and some relevant configuration files. Could you please check if something is wrong? If you need any additional files, please, let me know.<br><br>Thanks in advance, David.<br></div>