<div dir="ltr">Baron - <div><br></div><div> There are a couple of known ways to handle this, depending on the details of your architecture.</div><div><br></div><div> How the Shibboleth IDP authenticates account holders is (mostly) independent of how it responds to the authentication request from service providers. (The caveat is if you'd like to use Entra for attributes... ) </div><div><br></div><div> The following URLs may help:</div><div><br></div><div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div><a href="https://learn.microsoft.com/en-us/entra/architecture/multilateral-federation-solution-two">https://learn.microsoft.com/en-us/entra/architecture/multilateral-federation-solution-two</a></div><div><br></div><div><a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1467056889/Using+SAML+Proxying+in+the+V4+Shibboleth+IdP+to+connect+with+Azure+AD">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1467056889/Using+SAML+Proxying+in+the+V4+Shibboleth+IdP+to+connect+with+Azure+AD</a></div></blockquote><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div>(This is a V4 document, but it should apply to V5 without too much difficulty.)</div><div><br></div></blockquote>Steve.</div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, Jul 24, 2025 at 4:43 PM Baron Fujimoto via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div>We've recently learned that we will be adopting Entra as for authentication and SSO institution-wide. We currently use both Apereo CAS and the Shibboleth IdP to provide SSO. We actually currently use CAS for authn for our IdP as well, so we can present a single unified UX to our users, but we were in the process of consolidating these services into a unified Shibboleth IdP service for both CAS, SAML, and other protocols as needed. Needless to say, this has thrown quite the wrench into our work.<br><br>We will still need to support both the SAML and CAS protocols, because we have many SPs and applications already integrated with them for SSO. It is our understanding that Entra supports neither SAML nor CAS, so we will have to have some way to put Entra in front of them for the initial authentication, then pass on the results for the rest of the workflow to the backend IdP service to handle these protocols. (I'm not sure what the term of art would be for this, "authentication proxy" or something similar?)<br><br>Our initial research suggests that putting Entra in front of the Shibboleth IdP is something that's generally possible (at least for SAML?), but I couldn't find anything that went into much detail. We would greatly appreciate any pointers or tips on where to start, or even good questions we should be asking about this. One big question that comes up immediately for us, is assuming we can use the IdP for the SAML stuff, does it also work when the IdP is handling CAS as well? The answer to this would determine whether we should even continue with our attempts to bring CAS under the aegis of the IdP, or whether we need to maintain a separate Apereo CAS for this.<br><br>FWIW, I did find the following in the IdP wiki:<br clear="all"></div><div><br></div><div>- includes a note about "Intra" [sic]</div><div> <<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration" target="_blank">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration</a>>></div><div><br></div><div>- CAS Proxy info, deprecated, references ProxyValidator, but can't find add'l info<br> <<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199506501/CASProxyAuthenticatorDeprecation" target="_blank">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199506501/CASProxyAuthenticatorDeprecation</a>><br></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature"><div dir="ltr"><font face="arial, sans-serif">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> ::: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum descendus pantorum</font></div></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>