<div dir="ltr">Hi again,<br><br>Thanks to all for your replies.<br><br>The suggested documentation was read and used to configure this scenario, but due to the different software versions, we found some problems/erratas. We workaround them, but maybe they are causing the problems.<br><br>There are no errors in the web browser. After authenticating in the Shibboleth login page, the browser is redirected to the Office 365 login page agaĆ­n, and that's all.<br><br>We are going to review again the AD FS 3 side using the suggested documentation, even the parts related to AD FS 2.<br><br>Apart from this, two questions:<br><br>- The "Azure AD Connect" tool to deploy the AD FS and federate your domain, installs a WAP (Web Application Proxy) server that is the intermediary between AD FS 3 and the cloud. Maybe Shibboleth must talk with this WAP server and not to AD FS 3 directly. What do you think about this?<br><br>- The only error/warning message in the logs is:<br><br>2016-02-23 13:06:08,011 - WARN [net.shibboleth.idp.authn.impl.AttributeSourcedSubjectCanonicalization:146] - Profile Action AttributeSourcedSubjectCanonicalization: No attributes found, canonicalization not possible<br><br>Do you consider relevant this warning?<br><br><br>Thanks in advance, David.<br></div>