<div dir="ltr">Yep, I agree. </div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Feb 28, 2017 at 9:43 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> Never actually touched ECP configuration before... but that is a great hint!<br>
> Hmm..then might be ADAL it is...<br>
<br>
</span>ADAL is web based.<br>
<br>
ECP is used in O365 to support non-web mail clients on other platforms via a proxy and they use the same approach with a WS-Trust proxy if you use ADFS. In short, Microsoft does not support a model whereby you can prevent the passwords from reaching their servers. In my view, that renders most of this a waste of time, since if you sync passwords to them, they're stored in a pretty secure fashion. The risk is in transit, and somebody attacking those proxies on their network as a choke point to harvest millions of passwords, and that is unavoidable unless you just force webmail on people and block mobile mail clients.<br>
<br>
SSO is nice, but is it worth the hassle of dealing with O365 in the end if you still end up handing them your passwords? I think reasonable people can differ on that and people should certainly understand this issue before they make a decision.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">Best,<br>Zico</div>
</div>