<div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Oct 20, 2020 at 1:03 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 10/20/20, 3:46 PM, "users on behalf of Ben Poliakoff" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:benp@reed.edu" target="_blank">benp@reed.edu</a>> wrote:<br>
<br>
>    Perhaps there's something else in the new SP metadata file that is causing the IDP to suppress the emailAddress<br>
> formatted nameid?<br>
<br>
Or perhaps there's an activationCondition attached to the generator of the email format limiting it to only the old SP, or the underlying attribute isn't released to the new SP and the generator isn't looking at unfiltered data.<br></blockquote><div><br></div><div>Bingo! That was it. There was indeed an activationCondition, and then I found the bean for that condition in global.xml. Once I added the new Adobe SP to the list of candidates that condition the authentication test started working properly (using the email based nameid as the username).</div><div><br></div><div>Thank you so much for your help!</div><div><br></div><div>Ben</div></div></div>