<div dir="ltr">Hi Muhammad, <div><br></div><div> Thanks for the reply. I just want to make sure I understand you correctly. You deployed only the ADFS proxy -- you didn't actually need to build an ADFS cluster in your domain? So the proxy handled the WS-Federation requests, but Shib handled the SAML auth still? If that's correct, that certainly seems less daunting than running an AD FS cluster just to support Autopilot. </div><div><br></div><div>-Matt</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, 30 Oct 2024 at 11:26, Muhammad Farhan SJAUGI <<a href="mailto:farhan@sifulan.my">farhan@sifulan.my</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi Matt,<br>
<br>
I haven't tested yet with MS Autopilot, but I managed to make<br>
Shibboleth IdP work with the MS OOBE.<br>
<br>
What I did was, I put the ADFS (proxy) server in between Shibboleth<br>
IdP and Entra ID, and used WS-Fed/WS-Trust to connect the ADFS and<br>
EntraID.<br>
<br>
However, you may need to list some MS authentication context,<br>
particularly <a href="http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password" rel="noreferrer" target="_blank">http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password</a><br>
in the Shibboleth IdP's supported AuthenticationContext.<br>
<br>
So far our method works well with Office365, Entra Join, and also OOBE.<br>
<br>
Regards<br>
<br>
--<br>
Ts. Muhammad Farhan Sjaugi, S.Kom. M.Sc.<br>
VP (Engineering and Services)<br>
SIFULAN Malaysian Access Federation<br>
Email: <a href="mailto:farhan@sifulan.my" target="_blank">farhan@sifulan.my</a> | Website: <a href="https://www.sifulan.my" rel="noreferrer" target="_blank">https://www.sifulan.my</a><br>
PGP Fingerprint: 9AA0 1861 0921 3EBD 4E30 716A 1F71 FC55 49CD D06C<br>
MBOT: GT20040131 | ORCID: <a href="https://orcid.org/0000-0001-8497-1768" rel="noreferrer" target="_blank">https://orcid.org/0000-0001-8497-1768</a><br>
Credly: <a href="https://www.credly.com/users/muhammad-farhan-sjaugi" rel="noreferrer" target="_blank">https://www.credly.com/users/muhammad-farhan-sjaugi</a><br>
<br>
On Wed, Oct 30, 2024 at 11:05 PM Matt Brennan via users<br>
<<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:<br>
><br>
> Hi Folks,<br>
><br>
> Has anyone gotten MS Autopilot to work while federating Entra (formerly known as Azure AD) to Shibboleth? We're running into an issue right now where we get an error at the very first login screen which says the identity was not found in the directory.<br>
><br>
> Our implementation partner is telling us that this will never work because the IdP needs to support WS-Trust (referencing this article: <a href="https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join" rel="noreferrer" target="_blank">https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join</a>).<br>
><br>
> All the posts I'm finding agree, but they're also all several years old. I just wanted to see if anyone had made this work recently -- either through Shibboleth, or by some hackery to let the user authenticate via Entra only for Autopilot.<br>
><br>
> Thanks,<br>
> Matt<br>
> --<br>
> For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>