Client IDP Send à SAML Response -> Azure B2C (SP) -> Consume SAML Response

TUHIN SINHA 20 Reputation points
2023-05-30T17:27:15.6166667+00:00

Client IDP : External IDP initiating the IDP flow. (Not Azure B2C any external IDP )

Azure B2C : Acting as Service Provider

We are looking for below IDP Flow in terms of Client IDP supporting IDP initiated flow. The originator is Client IDP.

Client IDP Send à SAML Response -> Azure B2C (SP) -> Consume SAML Response -> Registered Application

 

Our understanding is that below article is implementing above flow as mentioned below . Please review it. 

https://medium.com/the-new-control-plane/using-azure-ad-b2c-as-a-saml-idp-with-the-idp-initiated-flow-d80e76864474

There is another https://learn.microsoft.com/en-us/azure/active-directory-b2c/saml-service-provider-options?pivots=b2c-custom-policy#configure-idp-initiated-flow which is contradicting.

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,662 questions
0 comments No comments
{count} votes

Accepted answer
  1. Akshay-MSFT 16,126 Reputation points Microsoft Employee
    2023-05-31T08:31:31.0433333+00:00

    @TUHIN SINHA

    Thank you for posting your query on Microsoft Q&A.

    From above description I could understand that you are looking for IDP initiated flow with a federated (external/3rd party) IDP in Azure B2C. Please do correct me if this is not the case by responding in the comments section.

    As mentioned in our documentation referring Configure IdP-initiated flow, we don't currently support scenarios where the initiating identity provider is an external identity provider federated with Azure AD B2C, such as Active Directory Federation Services or Salesforce. IdP-initiated flow is supported only for local account authentication in Azure AD B2C.

    The reference given in 3rd party document is not tested by or validated by Microsoft. I would recommend you to test it with 2-5 test users only as any configurational break-fix issues would not be assisted by Microsoft support.

    I would recommend to use the SP initiated flow if possible and post this request on our Feedback portal which is monitored by our Dev Team.

    Please do let me know if you have any queries by responding the comments section.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer" (Yes), and share your feedback if the suggestion answers you’re your query. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful