<div dir="ltr">All,<div><br></div><div>Today we have Shibboleth as our primary IdP.  We integrate with Azure acting as an SP for O365 and portal access, as well as Slack and Service Now(Everything else is federated or integrated directly against shib).  So a user logging into a service integrated with Azure does HRD, is redirected to Shib, authenticates, then is returned to Azure, who translates the shib SAML assertion/session into Azure ones and allows the user to log in.<div><br></div><div>I've been asked about the feasibility of adjusting the process, where Azure becomes the primary IdP and all SSO requests going to Shib are redirected to Azure for authentication, then the returning assertion is repackaged as a shib assertion and returned to the SP.  Azure-integrated services would go back to the SP after AZ authn.</div><div><br></div><div>Is that something that is possible with Shibboleth today?  If so, what is the best way to go about this?</div><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div dir="ltr">Jeffrey Williams </div><div dir="ltr">Identity Engineer<br>Identity & Access Services<br><a href="https://its.uncg.edu" target="_blank">https://its.uncg.edu</a></div></div><div dir="ltr"><br></div><div dir="ltr"><img src="https://uncgcdn.blob.core.windows.net/email/UNCGLogo.png"><br></div></div></div></div></div></div></div></div></div></div></div>