4
© 2020 SWITCH | 1 Azure AD – O365 Integration Thomas Bärecke [email protected] Zürich, 20.05.2020

Azure AD –O365 Integration · 2020-05-20 · Microsoft Azure AD with Pass-Through-Authentication (PTA) Microsoft Cloud SWITCH edu-ID (productionfederation) Organisation SWITCH (edu-ID

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Azure AD –O365 Integration · 2020-05-20 · Microsoft Azure AD with Pass-Through-Authentication (PTA) Microsoft Cloud SWITCH edu-ID (productionfederation) Organisation SWITCH (edu-ID

© 2020 SWITCH | 1

Azure AD – O365 Integration

Thomas Bä[email protected]ürich, 20.05.2020

Page 2: Azure AD –O365 Integration · 2020-05-20 · Microsoft Azure AD with Pass-Through-Authentication (PTA) Microsoft Cloud SWITCH edu-ID (productionfederation) Organisation SWITCH (edu-ID

© 2020 SWITCH | 2

Microsoft Azure AD with Pass-Through-Authentication (PTA)

Microsoft Cloud SWITCH edu-ID (production federation)

Organisation SWITCH(edu-ID adopted)

Admin

0. user provisioningwith scripts to AAD User

1. Access attempt(unauthenticated)

2. Home realmdiscovery(WAYF)

3. Authentication

4. Service access

(authenticated)

Azure AD

Page 3: Azure AD –O365 Integration · 2020-05-20 · Microsoft Azure AD with Pass-Through-Authentication (PTA) Microsoft Cloud SWITCH edu-ID (productionfederation) Organisation SWITCH (edu-ID

© 2020 SWITCH | 3

Limitations and workarounds

• Limitation: Bilateral non-standard configuration• Current solution: Special configuration on SWITCH edu-ID

IdP• Long-term solution: Proxy

• Limitation: One Microsoft Custom Domain per SAML-IdP only

• Shortly available solution: One proxy per domain

Page 4: Azure AD –O365 Integration · 2020-05-20 · Microsoft Azure AD with Pass-Through-Authentication (PTA) Microsoft Cloud SWITCH edu-ID (productionfederation) Organisation SWITCH (edu-ID

© 2020 SWITCH | 4

Multiple instances for multiple domains

Bundled together in Shibboleth IdP V4.0

Proxy architecture

SWITCH edu-ID IdP

ShibSP

ShibIdP

Azure AD / O365

ShibSP

ShibIdP

SWITCHaai federationMicrosoft