<div dir="ltr"><div>Hello! I'm trying to integrate Microsoft Azure AD with Shibboleth v5.1.3, but I'm encountering some issues. Could anyone offer some guidance?<b><br></b><br>We completed all steps of the procedure outlined at <a target="_blank" class="gmail-c-link gmail-c-mrkdwn__identity_trigger" href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/2783936889/SAML+Proxying+EntraID+Azure+with+the+Shibboleth+IdP" rel="noopener noreferrer">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/2783936889/SAML+Proxying+EntraID+Azure+with+the+Shibboleth+IdP</a>. The objective was to perform IDP Proxying with <b>Shibboleth V5.1.3 and Microsoft Azure AD.</b>
 During testing, a Shibboleth SP showed an error with "StatusMessage: An
 error occurred." The logs contained the following message:<span aria-label="" class="gmail-c-mrkdwn__br"></span><b><br><br>ERROR
 [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:76] - 
Profile Action SelectSubjectCanonicalizationFlow: No potential flows 
left to choose from, canonicalization will fail</b><span aria-label="" class="gmail-c-mrkdwn__br"></span><br><br>We
 increased the log level for further analysis and found that the 
Shibboleth IDP was not passing attributes due to an inconsistency when 
attempting to map 'azureName':<span aria-label="" class="gmail-c-mrkdwn__br"></span><b><br><br><br>DEBUG
 [net.shibboleth.idp.attribute.filter.AttributeRule:149] - Attribute 
filtering engine 
'/AttributeFilterPolicyGroup:ShibbolethFilterPolicy/AttributeRule:_a0798fb6385d2de9a09c0a44397262e1'
 Filtering values for attribute 'azureName' which currently contains 1 
values</b><br><b>DEBUG 
[net.shibboleth.idp.attribute.filter.matcher.saml.impl.AbstractMatchesShibMDScopeMatcher:93]
 - Attribute Filter 
'/AttributeFilterPolicyGroup:ShibbolethFilterPolicy/PermitValueRule:_29d4f0f50773b5d6d70e7dd298b68a96':
 Applying shibmd scope comparison to all values of Attribute 'azureName'</b><br><b>DEBUG
 
[net.shibboleth.idp.attribute.filter.matcher.saml.impl.AbstractMatchesShibMDScopeMatcher:119]
 - Attribute Filter 
'/AttributeFilterPolicyGroup:ShibbolethFilterPolicy/PermitValueRule:_29d4f0f50773b5d6d70e7dd298b68a96':
 returning 0 values</b><br><b>DEBUG 
[net.shibboleth.idp.attribute.filter.AttributeRule:158] - Attribute 
filtering engine 
'/AttributeFilterPolicyGroup:ShibbolethFilterPolicy/AttributeRule:_a0798fb6385d2de9a09c0a44397262e1'
 Filter has permitted the release of 0 values for attribute 'azureName'<br><br></b></div><div>Thank you all in advance!<br></div><br><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><i><b>Luan Trindade</b></i><br></div></div></div>