<div dir="ltr"><div>We've recently learned that we will be adopting Entra as for authentication and SSO institution-wide. We currently use both Apereo CAS and the Shibboleth IdP to provide SSO. We actually currently use CAS for authn for our IdP as well, so we can present a single unified UX to our users, but we were in the process of consolidating these services into a unified Shibboleth IdP service for both CAS, SAML, and other protocols as needed. Needless to say, this has thrown quite the wrench into our work.<br><br>We will still need to support both the SAML and CAS protocols, because we have many SPs and applications already integrated with them for SSO. It is our understanding that Entra supports neither SAML nor CAS, so we will have to have some way to put Entra in front of them for the initial authentication, then pass on the results for the rest of the workflow to the backend IdP service to handle these protocols. (I'm not sure what the term of art would be for this, "authentication proxy" or something similar?)<br><br>Our initial research suggests that putting Entra in front of the Shibboleth IdP is something that's generally possible (at least for SAML?), but I couldn't find anything that went into much detail. We would greatly appreciate any pointers or tips on where to start, or even good questions we should be asking about this. One big question that comes up immediately for us, is assuming we can use the IdP for the SAML stuff, does it also work when the IdP is handling CAS as well? The answer to this would determine whether we should even continue with our attempts to bring CAS under the aegis of the IdP, or whether we need to maintain a separate Apereo CAS for this.<br><br>FWIW, I did find the following in the IdP wiki:<br clear="all"></div><div><br></div><div>- includes a note about "Intra" [sic]</div><div>  <<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration</a>>></div><div><br></div><div>- CAS Proxy info, deprecated, references ProxyValidator, but can't find add'l info<br>  <<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199506501/CASProxyAuthenticatorDeprecation">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199506501/CASProxyAuthenticatorDeprecation</a>><br></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><font face="arial, sans-serif">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> ::: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum descendus pantorum</font></div></div></div>