<div dir="ltr">Alberto -<div><br></div><div>  Generally, when the question is "Is it possible for Shibboleth to ...?", the answer is yes.  That said, this is a topic where I think you should spend time thinking about whether you SHOULD attempt it.</div><div><br></div><div>  The examples that I could find  [1][2] do not seem to fully match what you are seeking.  For example, both assume the directories would be using the same application (and schema), if I am reading your question correctly, you would have two different types of directory.</div><div><br></div><div>  Authentication should be the "easy" part, since it would primarily be taking the provided information and attempting to search and/or bind with the directory. Once you are able to get authentication working, you will likely need to tackle how attribute resolution and other parts of your post-authentication process works.</div><div><br></div><div>  Testing would be critical... you specifically mention "exists"...</div><div><br></div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div>what should happen if (when) there is an overlap in the directories, especially when there's a mismatch in passwords (e.g. authentication fails) or account status (e.g. the account exists in both directories, but is disabled or locked-out in one of them)?</div><div><br></div></blockquote><blockquote style="margin:0 0 0 40px;border:none;padding:0px">Are both directories providing enough information to accurately manage unique identifiers? <br><br></blockquote>Additionally, if the end goal is to allow account holders in two separately managed and distinctly "scoped" identity stores to authenticate to a single application, the better approach would likely be stand up a separate identity provider for each identity store and leverage discovery (or if the application doesn't support multiple identity providers, a middle-thing) to direct the authentication request to the proper location.<div><br></div><div>Ultimately, while this is likely technically possible with the Shibboleth IDP, whether you SHOULD or not is a much bigger discussion than the technical implementation and dependent on the details specific to your environment and goals, something that is normally best handled through some form of professional services conversation.</div><div><br></div><div>Steve.</div><div><br></div><div>[1] - <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505688/LDAPAuthnConfiguration#Chaining-LDAP-validators">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505688/LDAPAuthnConfiguration#Chaining-LDAP-validators</a></div><div>[2] - <a href="https://github.com/ConsortiumGARR/idem-tutorials/blob/master/idem-fedops/HOWTO-Shibboleth/Solutions/HOWTO%20Configure%20a%20Shibboleth%20IdP%20v4.x%20to%20authenticate%20users%20existing%20on%20different%20LDAP%20Servers.md">https://github.com/ConsortiumGARR/idem-tutorials/blob/master/idem-fedops/HOWTO-Shibboleth/Solutions/HOWTO%20Configure%20a%20Shibboleth%20IdP%20v4.x%20to%20authenticate%20users%20existing%20on%20different%20LDAP%20Servers.md</a>  (Note: HOWTO is based on the now unsupported IDP 4)</div><div><br></div><div><br></div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Wed, Aug 6, 2025 at 10:52 AM Alberto DeAngelis via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg-8197875029092533971">




<div dir="ltr">
<div style="line-height:normal;margin:0px;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Hello,</div>
<div style="line-height:normal;margin:0px;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="line-height:normal;margin:0px;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Would it be possible to do a “Search Active Directory” and then “Search LDAP directory”. So for instance, if a user exists in Active Directory then Shib authentication. If the user doesn’t exist in Active Directory, then it searches LDAP. Is that possible?</div>
<div style="line-height:normal;margin:0px;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="line-height:normal;margin:0px;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Thank you,</div>
<div style="line-height:normal;margin:0px;font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Alberto</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div id="m_-5864623708239714619Signature">
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div><span style="font-family:Georgia,sans-serif;font-size:14px;color:rgb(4,106,56);font-weight:bolder">Alberto DeAngelis '20 '22</span><span style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)"><br>
</span><span style="font-family:Georgia,sans-serif;font-size:14px;color:rgb(4,106,56)"><i>Database Administrator<br>
Information Technology Services</i></span><span style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)"><br>
</span><span style="font-family:Georgia,sans-serif;font-size:14px;color:rgb(57,57,57)"><img style="width: 170px; height: 54px; max-width: 780px; box-sizing: border-box;" height="54" width="170" alt="Manhattan University Logo/Shield"></span><span style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)"><br>
</span><span style="font-family:Georgia,sans-serif;font-size:14px;color:rgb(57,57,57)">Riverdale, NY 10471</span><span style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)"><br>
</span><span style="font-family:Georgia,sans-serif;font-size:14px;color:rgb(57,57,57)">Phone: 718-862-7871</span><span style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)"><br>
</span><span style="font-family:Georgia,sans-serif;font-size:14px;color:rgb(50,98,149)"><u><a style="color:rgb(50,98,149);text-align:left" href="mailto:adeangelis01@manhattan.edu" target="_blank">adeangelis01@manhattan.edu</a></u></span><span style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)"><br>
</span><span style="font-family:Georgia,sans-serif;font-size:14px;color:rgb(50,98,149)"><u><a style="color:rgb(50,98,149);text-align:left" href="http://www.manhattan.edu/" target="_blank">www.manhattan.edu</a></u></span></div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
</div>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></blockquote></div>