Configuring Microsoft Entra ID (Azure) SAML-based SSO for SAFIRE
While it is possible to connect Microsoft Entra ID directly into SAFIRE, this has several caveats you need to be aware of. To help you make an informed decision, the info boxes in this document highlight some of the things you need to consider. Read through it carefully before starting your implementation.
Microsoft recommends integrating Entra ID into SAFIRE via a SAML Proxy such as Shibboleth, which mirror’s the R&E federation communty’s guidence. (Some SAFIRE providers opt to use SimpleSAMLphp for this instead.) Doing this avoids many of the caveats highlighted below.
…