<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:193084290;
        mso-list-template-ids:1346525282;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><a name="_MailEndCompose">Hi All,<o:p></o:p></a></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose">I came across all these issues as well - I think this is a pretty good summary and it would be great to get the wiki updated.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose">Mostly recently I came up against the requirement for unique URI settings when setting up SSO for multiple e-mail domains.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose">We ended up deploying a second IdP instance using a different port, which made the entity ID unique.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose">I looked at doing something dynamic with a single instance but felt it was potentially too involved and I didn’t have the time to spend on it.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose">We also had to configure basic authentication for ECP and have had issues with Mac’s registering desktop software. I’ll definitely check out the configuration that Nate referenced.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><span style="color:#44546A">Thanks,<o:p></o:p></span></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><o:p> </o:p></span></p>
<p class="MsoNormal" style="vertical-align:baseline"><span style="mso-bookmark:_MailEndCompose"><b><span style="font-size:12.0pt;color:#1F3864">Tom O’Neill</span></b></span><span style="mso-bookmark:_MailEndCompose"><span style="font-size:12.0pt;color:#3B3838"><o:p></o:p></span></span></p>
<p class="MsoNormal"><span style="mso-bookmark:_MailEndCompose"><o:p> </o:p></span></p>
<span style="mso-bookmark:_MailEndCompose"></span>
<p class="MsoNormal"><b>From:</b> users [mailto:users-bounces@shibboleth.net] <b>
On Behalf Of </b>Rob Gorrell<br>
<b>Sent:</b> Wednesday, October 11, 2017 8:16 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Office 365 + Shibboleth ?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">We are a school that has federated AAD using Shibb/SAML and stuck with that approach since we started with O365. The integration itself was relatively straightforward as long as you don't mind some very basic
 PowerShell and of course forgoing things like encrypted assertions. Usability was initially a rocky road prior to Office 2016 and modern authentication, but since then, we've had no problem signing into Office apps using SAML... both on the Mac and PC sides.
 In the interest of full disclosure, we have turned off Exchange Online (we are a Google Apps school for email), so avoid many problems there. But in terms of using the mainstream apps (Word, Excel, Powerpoint Online, OneDrive, Skype for Business) we're all
 good. <o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt">Things I've noticed that are still problemmatic for us without ADFS... we cannot Azure AD join a Win 10 box for Entune management, that is one of the bigger ones for us at the moment. We are also looking to
 do more in the Azure Cloud where federating with SAML might pose a problem... for instance, SQL PaaS... database authentication works with AAD, but only with password sync or ADFS. Things like that.<o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt">-Rob<o:p></o:p></p>
<div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p> </o:p></p>
</div>
</div>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">On Wed, Oct 11, 2017 at 4:58 PM, Robert Rust <<a href="mailto:robert.j.rust@uwrf.edu" target="_blank">robert.j.rust@uwrf.edu</a>> wrote:<o:p></o:p></p>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">A couple of questions around Office 365 with Shibboleth authentication. I’m looking at options for our setup as we need to implement multi-factor authentication and I at the very
 least need to replace our ADFS 2.0 installation.  I’ve found information on upgrading ADFS, but given we’re focusing on Shib for our other apps, I’d prefer to switch to Shibboleth since setting up the same level of availability with ADFS that we already have
 for Shib would be more of a challenge I think.<o:p></o:p></p>
<ol start="1" type="1">
<li class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
For those of you using Shib + Office 365, have you found any setups that routinely don’t work or other gotchas?  I saw traffic a while back suggesting that activation of desktop installations of Office software on Macs didn’t work. I also recall reading somewhere
 that the Shib signing certificate would need to be a commercially issued one in order to work with Office 365.<o:p></o:p></li><li class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo1">
Were there any guides that you used to set it up in the first place? The closest I’ve found is a guide for Dynamics 365 (<a href="https://docs.microsoft.com/en-us/dynamics365/customer-engagement/portals/configure-saml2-settings)" target="_blank">https://docs.microsoft.com/en-us/dynamics365/customer-engagement/portals/configure-saml2-settings)</a><o:p></o:p></li></ol>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">I do have a test environment I can break things in to try this out, but I’d prefer not to fly blind.<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Robert
<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:10.5pt;color:black">-- </span><o:p></o:p></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:10.5pt;color:black">~~~~~~~~~~~~~~~~~~~~~~~~~</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:10.5pt;color:black">Robert J. Rust</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:10.5pt;color:black">Systems Administrator</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:10.5pt;color:black">Division of Technology Services</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:10.5pt;color:black">Univ. of Wisc. - River Falls</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:10.5pt;color:black">~~~~~~~~~~~~~~~~~~~~~~~~~</span><o:p></o:p></p>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:10.5pt;color:black"><img border="0" width="282" height="46" style="width:2.9375in;height:.4791in" id="m_3560622431116437744_x005f_x0000_i1025" src="https://www2.uwrf.edu/static/images/email-wordmark.png" alt="https://www2.uwrf.edu/static/images/email-wordmark.png"></span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</blockquote>
</div>
<p class="MsoNormal"><br>
<br clear="all">
<br>
-- <o:p></o:p></p>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal">Robert W. Gorrell<br>
IT Manager, Identity and Access Management <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">University of NC at Greensboro<br>
336-334-5954<br>
PGP Key ID B36DB0CA<o:p></o:p></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</body>
</html>