<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
span.EmailStyle18
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Hi Patrick,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I’ve also opened a case with Microsoft about this (SR # 116080914525742) and was told to install the Azure Authenticator app. That seems to fix the problem for me but others are still seeing this. It is being
 discussed on the <a href="mailto:offic365@ucdavis.edu">offic365@ucdavis.edu</a> listserv.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I’ve asked the MS PSE for more information about what’s going on, specifically what the Authenticator app is doing. I have not heard back on that.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Also, one of our IAM team members, Michael Brogan, attempted to troubleshoot by setting up a proxy server. He only saw one difference between the two requests (from the old OneDrive for Business app that works
 without Authenticator and the new OneDrive app again without Authenticator) and the only difference was the presence of a new, non-standard, header requesting MS-PKAP auth. That is a proprietary cert-based device registration/authentication protocol. I presume
 the Authenticator app is leveraging this new protocol.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">We are running ADFS 2.0 so I would be surprised if it recognized the new MS-PKAP header and acted on it, but perhaps this was added via an update.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Clearly testing with ADFS using Shib is not part of the MS testing matrix.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">    Eric Kool-Brown<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">    Software Engineer<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">    University of Washington - IT Identity and Access Management<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users [mailto:users-bounces@shibboleth.net] <b>
On Behalf Of </b>Patrick Le<br>
<b>Sent:</b> Wednesday, August 17, 2016 12:00 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Office 365 -> ADFS ->Shibboleth iOS problems?<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Does anyone Federate their office 365 environment with ADFS but treat ADFS as a relying party to Shibboleth? If so, have you experienced any issues with IOS app authentication in the last week with Office apps (Word, Excel, PowerPoint,
 etc.).<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We’ve been seeing some issues since Thursday when Microsoft released updates to their IOS apps. When Shib gets the auth request from ADFS, Shib throws an error:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">14:24:29.750 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:400] - Error decoding authentication request message<o:p></o:p></p>
<p class="MsoNormal">org.opensaml.ws.message.decoder.MessageDecodingException: No SAMLRequest or SAMLResponse query path parameter, invalid SAML 2 HTTP Redirect message<o:p></o:p></p>
<p class="MsoNormal">        at org.opensaml.saml2.binding.decoding.HTTPRedirectDeflateDecoder.doDecode(HTTPRedirectDeflateDecoder.java:98) ~[opensaml-2.6.0.jar:na]<o:p></o:p></p>
<p class="MsoNormal">        at org.opensaml.ws.message.decoder.BaseMessageDecoder.decode(BaseMessageDecoder.java:79) ~[openws-1.5.0.jar:na]<o:p></o:p></p>
<p class="MsoNormal">        at org.opensaml.saml2.binding.decoding.BaseSAML2MessageDecoder.decode(BaseSAML2MessageDecoder.java:70) ~[opensaml-2.6.0.jar:na]<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We’ve spent the last three days with Microsoft support and have not gotten anywhere with them. We tell them we’re missing the query path from ADFS to return the auth request to but they keep telling auth the saml request is the same between
 both old and new versions. Funny thing is, when we try a device with the previous app versions prior to Thursday, authentication works fine. Yet they still insist that nothing within the authentication stack was changed on the app side even though there’s
 clearly a difference in user experience. <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Just seeing if anyone with a similar setup is seeing the same things and if you discovered a workaround.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Patrick <o:p></o:p></p>
</div>
</div>
</body>
</html>