<div dir="ltr">It's entirely possible I've reversed the directional terminology; I was thinking of it from the user's perspective where they would have Entra as the login UX, but the SPs and applications are still interacting with the IdP. Would this be proxying the authentication from the IdP's perspective?<div><br></div><div>Thank you for the confirmation on the references as well as the pointers to the Microsoft and IdP KB references. I'll take a closer look now that I know that's the path forward. Hopefully I can begin to connect the dots and flesh things out between the general SAML Authn Configuration page and the specific IdPv5 KB example for Entra. Hopefully in the process it will become clearer how this applies to the CAS aspects. I'm sure I'll have more questions when I know more about what I don't know and can ask more intelligent questions about it.</div><div><br></div><div>But thank you for at least providing us for now with a baseline confidence that we can proceed with our CAS protocol unification efforts and that we have a viable path forward with this.<br><div><br></div><div><br></div><div><br></div><div><br></div></div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, Jul 24, 2025 at 11:35 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">I kind if suspect you're reversing the normal directonal terminology.<br>
<br>
Putting Entra "in front" would mean integrating applications against Entra and authenticating users to Entra with Shiibboleth and I imagine that's perhaps not possible. Entra probably can't delegate to another SAML IdP. I could be wrong.<br>
<br>
Proxying authentication of Shibboleth to Entra is very trivial. The docs for that are the ones you found. The KB articles are a supplement, there's one for V4 and one for V5, but they are not the primary source.<br>
<br>
The IdP can proxy authentication to anything else but still issue CAS tickets or SAML assertions out without any problems.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div><div><br clear="all"></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature"><div dir="ltr"><font face="arial, sans-serif">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> ::: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum descendus pantorum</font></div></div>