<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">We have been looking at this a bit and Github seems to want to use SCIM to automate invitations into Organizations. Unfortunately, the one that we have available AzureAD does not support AzureAD as the SCIM provider and a direct integration
 with Shibboleth. You get a “Unsupported IdP” error when you try to go through the set up. They seem to want you to use their application integration in the Azure AD marketplace (or whatever it’s called these days).<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><a href="https://docs.github.com/en/github/setting-up-and-managing-organizations-and-teams/about-scim">https://docs.github.com/en/github/setting-up-and-managing-organizations-and-teams/about-scim</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Since our AzureAD SSO is uses ADFS, and our ADFS uses Shibboleth as a claims provider trust, we’ll probably just go the native AzureAD route. From there we can synchronize Github Org memberships with AD Groups.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Is your desire to leave them as a member of the Org but deny their SAML auth? What about SSH keys, API access, etc.?
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:12.0pt;color:black">From: </span></b><span style="font-size:12.0pt;color:black">users <users-bounces@shibboleth.net> on behalf of "Schwendner, Joanne" <joanne_schwendner@brown.edu><br>
<b>Reply-To: </b>Shib Users <users@shibboleth.net><br>
<b>Date: </b>Wednesday, July 15, 2020 at 2:03 PM<br>
<b>To: </b>"users@shibboleth.net" <users@shibboleth.net><br>
<b>Subject: </b>GitHub access control<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><b><span style="font-size:9.0pt;font-family:"Arial",sans-serif;color:#FA4616">[External Email]</span></b>
<o:p></o:p></p>
</div>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" align="left" width="100%" style="width:100.0%">
<tbody>
<tr>
<td style="padding:0in 0in 0in 0in"></td>
</tr>
</tbody>
</table>
<div>
<div>
<p class="MsoNormal">Does anyone have experience with controlling access to individual Organizations in GitHub Cloud?  We would like to control access by using Grouper group memberships.  We are successfully using their SAML SSO support.  But... 
<o:p></o:p></p>
<div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">It seems the only attribute GitHub cares about is NameID.  We are currently passing our persistent ID in NameID.  If it's there, they get in. To block access for a user, we would have to NOT send NameID in the assertion, if that's even
 possible.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Is it possible to conditionally NOT send NameID depending on a user's other attributes?  Is there another way to manage GitHub Org access (besides manually)?<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
<div>
<p class="MsoNormal">Thanks.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">Joanne<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">---<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:#202124">Joanne Schwendner<br>
Senior Developer - </span><span style="color:#888888">Web, Integration, & Identity Services</span><span style="font-family:"Arial",sans-serif;color:#202124"><br>
Brown University</span> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</div>
</div>
</div>
</div>
</body>
</html>