Symantec Access Management

  • 1.  Integrate O365 with SAML 2 CA SSO 12.8

    Posted Oct 29, 2018 06:30 AM

    Hi All,

     

    Has anyone integrated O365/Azure using SAML 2.0. Please note, we already have WS-Fed integration setup. What i am looking here is for SAML integration with O365 having CA SSO as IDP and O365 as SP. If anyone has done this please share some document or please provide your views and ideas on how to achieve.

     

    HubertDennis, Kanishak1,

     

    Could you please assist on this?



  • 2.  Re: Integrate O365 with SAML 2 CA SSO 12.8

    Posted Oct 29, 2018 08:54 AM

    jschristiein

     

    I would suggest have a read on these blogs. Let is know if there are specific questions. There are details in these blogs.

     

    Microsoft Office 365 - CA Single Sign-On - 12.8 - CA Technologies Documentation  

    SM -O365 Federation 

    O365 Integration with CA SSO 



  • 3.  Re: Integrate O365 with SAML 2 CA SSO 12.8

    Posted Oct 29, 2018 10:05 AM

    HubertDennis

     

    We do already have this setup using WS-Federation, What we are looking is to achieve the same thing using SAML 2 IDP (CA SSO as IDP and O365 as SP).

     

    Is it possible?

     

    The reason is, we are trying to do a fall back from Kerberos to SAML, if Kerberos doesn't work !!!.. I know this is weird, but we want to try...

     

    BR,

    Joseph Christie



  • 4.  Re: Integrate O365 with SAML 2 CA SSO 12.8

    Posted Oct 29, 2018 10:30 AM

    jschristiein

     

    We haven't tested purely with SAML across the board, but if Microsoft/Azure supports SAML 2.0 HTTP POST, it is worth giving a try. Atleast for the passive profile it should be a BAU / OOB SAML 2.0 IdP --> SP Partnership. At this point in time don't know even if we get the Passive Profile to work, would it work with Active Profile (There is no provision for defining STS configuration within the SAML Partnership, as we have within the WSFED partnership).



  • 5.  Re: Integrate O365 with SAML 2 CA SSO 12.8
    Best Answer

    Posted Jan 24, 2019 04:27 AM

    Was able to achieve this having SAML as IDP to SP, with entity as remote SP and local IDP. And pass the assertion to cloud O365.

     

    thank you. HubertDennis