<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body lang="EN-GB" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">> I'm not following... You're running a SAML proxy (otherwise why would<o:p></o:p></p>
<p class="MsoNormal">> your IDP config be relevant to IDP selection?) and your IDP is the only<o:p></o:p></p>
<p class="MsoNormal">> one known to the protected services and in turn (as a SAML SP) relies<o:p></o:p></p>
<p class="MsoNormal">> on upstream IDPs for the actual authentication?<o:p></o:p></p>
<p class="MsoNormal">><o:p> </o:p></p>
<p class="MsoNormal">> How can you determine the IDP the subject should be sent to based on<o:p></o:p></p>
<p class="MsoNormal">> the subject's email address if the subject hasn't authenticated at an<o:p></o:p></p>
<p class="MsoNormal">> IDP to assert that email address to you in the first place?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Hi Peter,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks for your response.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Apologies I wasn’t clear – our IdP and those of our clients who use SSO are known to our SP. We are a multi-tenanted SaaS application. Most of our tenants use our IdP for authentication, but some use their own Azure Active Directory/Okta
etc. IdP. Our SP is configured with the metadata of all the involved IdPs. If a client uses IdP-initiated SSO, our IdP is not involved at all. However, if they go directly to our application, the SP doesn’t have enough information to know which IdP that user
should go to (IP address is not enough), so sends everyone to our IdP, which presents an email address entry field as the first stage in the login flow. User enters their email address, and we look it up and act based on the email domain. E.g. Client A will
use our IdP so <a href="mailto:user@client-a.com">user@client-a.com</a> will proceed to enter a password, but Client B uses their own IdP, and so entering
<a href="mailto:user@client-b.com">user@client-b.com</a> will redirect to our SP (session initiator URL), specifying the entity ID of Client B’s IdP as the URL parameter, for them to log into their IdP and return.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We don’t need to trust the email address at that stage, if a malicious user enters a client-b.com email address, they will fail to authenticate over at Client B’s IdP and get no further<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Kind regards,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Marc<o:p></o:p></p>
</div>
Taskize Limited registered address 33 Cannon Street, London, EC4M 5SB. Registered in England No. 7921239. This message may contain information that is privileged or confidential. If you are not the intended recipient please delete it and inform the sender immediately.
</body>
</html>