开发者

using a third party identity provider with Office 365

we are currently using an inhouse SSO solution, using 2-factor authentication, that generates SAML to allow SSO to google apps and salesforce. We are looking to allow support for Office 365.

I am looking at all the documentation for Office 365 and from what i see, it uses SAML, but only if provided by an ADFS.

Would it be possible to use Office 365 with a pure SAML solution? Or is it possible to use ADFS with another identity provider (so not an Active Directory).

I have seen a sample with Tivoli IP, but i do not quite understand the roles, if I understand it all correctly, it actually defers the actual authentication from ADFS to Tivoli, but is that correct? If that would be true, that would be nice :)

Aside of that, from my google-expedition I can see the following options to use our own SSO solution with Office 365:

  1. adapt the login page from ADFS (aspx) and add our 2fa solution there. (source)
  2. use Forefront UAG, but not sure what that exactly means (source)
  3. use a service that pretends to behave as ADFS (source --in the comments)
  4. use SAML to federate the authentication (if I understand correctly) (source)

From 3. i would conclude that开发者_Go百科 4. is not possible, but is that just old information and now no longer valid?

Thank you for any helpful insights :)


Technically speaking, there is nothing about Office 365 that requires ADFS. SSO can be done w/ any federation server that can send the right type of messages and tokens. (I know because I've done it.) If your SSO solution emits the proper type of data, you can use it. There might be Microsoft SLA and support issues w/ using a federation server other than ADFS. Check that first. If you do want to reuse your existing federation infrastructure and need help, shoot me a note.


Just make sure that the SAML solution supports both passive and active profile (ECP). Passive profile is required for web based sign-in. The active/ECP is required to support thick clients like Outlook, Thunderbird, etc. We've gotten both profiles to work.

0

上一篇:

下一篇:

精彩评论

暂无评论...
验证码 换一张
取 消

最新问答

问答排行榜