<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div>
<blockquote type="cite" class="">
<div class=""><span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">No,
 I don't know how the Apple mail app works but I presume that it is using the WS-Trust version of ECP or artifact binding. This is similar to how older versions of Outlook worked where the app itself prompts for creds and then sends them as part of session
 initiation (protected by SSL/TLS of course).</span><br style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class="">
</div>
</blockquote>
</div>
<br class="">
<div class="">It was, as far as I could tell, still doing ECP-spoofing here.</div>
<div class=""><br class="">
</div>
<div class="">The queries come in directly from Microsoft.  Outlook on iPhone worked fine, but Apple Mail didn't work on iPhone or Mac OS X.  We had no issues with a broken ECP except that.</div>
<div class=""><br class="">
</div>
<div class="">I'm pretty sure it's configurable by IdP name.  Microsoft maintains a mapping of domains to protocols and IdP's.</div>
</body>
</html>