<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Vincent,<div class=""><br class=""></div><div class=""><div><blockquote type="cite" class=""><div class=""><span style="font-family: Calibri, sans-serif; font-size: 11pt;" class="">but it appears they will only allow you to configure one Office365 domain per shibboleth IdP [entityId].</span></div></blockquote><div><br class=""></div><div>Interesting.  It’s not necessarily wrong or right, but it’s interesting.  I’m mostly responding as a digest form for others.</div><div><br class=""></div><div>You can configure your IdP to pull attributes from multiple sources, or to authenticate against multiple sources.  You can use a custom entityID with a specific relying party.  You can’t just arbitrarily configure two entityID’s; there’s just one field to use, and no basis for selection.</div><div><br class=""></div><div>I don’t know if you can use the principal name for entityID selection.  I’d imagine there’s a way.  That’s the heart of your question, along with actually having and enforcing the mapping associating users with the right domain and the right entityID.  If someone can answer that one…</div><div><br class=""></div><div>I won’t get into the WS-* stuff.  I would advise you to steer clear too, if you’ve got the choice.</div><div><br class=""></div></div>Take care,</div><div class="">Nate.</div></body></html>