<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Vincent,<div class=""><br class=""></div><div class=""><div><blockquote type="cite" class=""><div class=""><span style="font-family: Calibri, sans-serif; font-size: 11pt;" class="">but it appears they will only allow you to configure one Office365 domain per shibboleth IdP [entityId].</span></div></blockquote><div><br class=""></div><div>Interesting. It’s not necessarily wrong or right, but it’s interesting. I’m mostly responding as a digest form for others.</div><div><br class=""></div><div>You can configure your IdP to pull attributes from multiple sources, or to authenticate against multiple sources. You can use a custom entityID with a specific relying party. You can’t just arbitrarily configure two entityID’s; there’s just one field to use, and no basis for selection.</div><div><br class=""></div><div>I don’t know if you can use the principal name for entityID selection. I’d imagine there’s a way. That’s the heart of your question, along with actually having and enforcing the mapping associating users with the right domain and the right entityID. If someone can answer that one…</div><div><br class=""></div><div>I won’t get into the WS-* stuff. I would advise you to steer clear too, if you’ve got the choice.</div><div><br class=""></div></div>Take care,</div><div class="">Nate.</div></body></html>