<div dir="ltr"><div><div>We are a school that has federated AAD using Shibb/SAML and stuck with that approach since we started with O365. The integration itself was relatively straightforward as long as you don't mind some very basic PowerShell and of course forgoing things like encrypted assertions. Usability was initially a rocky road prior to Office 2016 and modern authentication, but since then, we've had no problem signing into Office apps using SAML... both on the Mac and PC sides. In the interest of full disclosure, we have turned off Exchange Online (we are a Google Apps school for email), so avoid many problems there. But in terms of using the mainstream apps (Word, Excel, Powerpoint Online, OneDrive, Skype for Business) we're all good. <br><br></div>Things I've noticed that are still problemmatic for us without ADFS... we cannot Azure AD join a Win 10 box for Entune management, that is one of the bigger ones for us at the moment. We are also looking to do more in the Azure Cloud where federating with SAML might pose a problem... for instance, SQL PaaS... database authentication works with AAD, but only with password sync or ADFS. Things like that.<br><br></div>-Rob<br><br><div><div><br><br></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Oct 11, 2017 at 4:58 PM, Robert Rust <span dir="ltr"><<a href="mailto:robert.j.rust@uwrf.edu" target="_blank">robert.j.rust@uwrf.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">







<div bgcolor="white" link="#0563C1" vlink="#954F72" lang="EN-US">
<div class="m_3560622431116437744WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">A couple of questions around Office 365 with Shibboleth authentication. I’m looking at options for our setup as we need to implement multi-factor authentication and I at the very least need to replace our
 ADFS 2.0 installation.  I’ve found information on upgrading ADFS, but given we’re focusing on Shib for our other apps, I’d prefer to switch to Shibboleth since setting up the same level of availability with ADFS that we already have for Shib would be more
 of a challenge I think.<u></u><u></u></span></p>
<ol style="margin-top:0in" start="1" type="1">
<li class="m_3560622431116437744MsoListParagraph" style="margin-left:0in"><span style="font-size:11.0pt">For those of you using Shib + Office 365, have you found any setups that routinely don’t work or other gotchas?  I saw traffic a while back suggesting
 that activation of desktop installations of Office software on Macs didn’t work. I also recall reading somewhere that the Shib signing certificate would need to be a commercially issued one in order to work with Office 365.<u></u><u></u></span></li><li class="m_3560622431116437744MsoListParagraph" style="margin-left:0in"><span style="font-size:11.0pt">Were there any guides that you used to set it up in the first place? The closest I’ve found is a guide for Dynamics 365 (<a href="https://docs.microsoft.com/en-us/dynamics365/customer-engagement/portals/configure-saml2-settings)" target="_blank">https://docs.microsoft.com/<wbr>en-us/dynamics365/customer-<wbr>engagement/portals/configure-<wbr>saml2-settings)</a><u></u><u></u></span></li></ol>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">I do have a test environment I can break things in to try this out, but I’d prefer not to fly blind.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Robert <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.5pt;color:black">-- <u></u><u></u></span></p>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;color:black">~~~~~~~~~~~~~~~~~~~~~~~~~<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;color:black">Robert J. Rust<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;color:black">Systems Administrator<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;color:black">Division of Technology Services<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;color:black">Univ. of Wisc. - River Falls<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;color:black">~~~~~~~~~~~~~~~~~~~~~~~~~<u></u><u></u></span></p>
</div>
<p class="MsoNormal"><span style="font-size:10.5pt;color:black"><img id="m_3560622431116437744_x0000_i1025" src="https://www2.uwrf.edu/static/images/email-wordmark.png" alt="https://www2.uwrf.edu/static/images/email-wordmark.png" width="282" height="46" border="0"></span><u></u><u></u></p>
</div>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div>Robert W. Gorrell<br>IT Manager, Identity and Access Management <br></div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div></div></div></div>
</div>