UPDATE! The community will be go into read-only on April 19, 8am Pacific in preparation for migration on April 21. Read more.
UPDATE! The community will be go into read-only on April 19, 8am Pacific in preparation for migration on April 21.Read more.
Lieutenant
Lieutenant
321 views

WSFED with multiple Office 365 Tenants

Guys, I have setup wsfed with 2 Office 365 tenants. However I have a requirements to pass a different set of attributes in another tenants but I can't figure out how, is it possible? Noticed that creating 2 seperate WS-Trust/Fed Service Provider won't help as it just goes to One. So one of my tenant was to remain GUID and MAIL as attr, but another tenant I need to use a seperate attr. Possible? Thanks

2 Replies
Knowledge Partner Knowledge Partner
Knowledge Partner

I don't think it is possible to have different attributes for different tenants, since this is only (let's say) one federation from NAM point of view.

But maybe this can be solved different way.

Do you have different users accessing different tenant (e.g. user A,B,C access to tenant1 and user D,E,F to tenant2), or is it same user that needs access to both tenants?

If those are different users, you can maybe use virtual attribute in attribute map and then calculate virtual attribute value based on user's properties?

If same user needs access to both tenants, maybe you can federate tenant1 using ws-fed and tenant2 using SAML. Then you can have different attribute sets. Please note that I haven't done that before, but it might be worth trying.

Of course, if you have servers to spare, you can set up additional NAM IDP cluster, federate each IDP cluster with each tenant and then do SAML federations between IDPs (done that before NAM was able to federate to multiple tenants)

 

Kind regards,

Sebastijan

0 Likes
Lieutenant
Lieutenant

@Sebastijanthanks i tried both method as your mentioned (for same user to 2 tenant scenarios) and it works.

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.