Federation for a partial population

Younes AITIFALI 1 Reputation point
2022-07-29T17:24:49.863+00:00

Greetings,

I want to know if it is possible to federate the authentication of a partial population that resides on AzureAD, using an external Identity Provider (PingFederate, Okta, ..)

The goal is to test this federation on a pilot population just on AzureAD production, before expanding it to the entire population.

Thank you in advance,

Microsoft Security | Active Directory Federation Services
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Dillon Silzer 57,826 Reputation points Volunteer Moderator
    2022-07-29T18:44:12.243+00:00

    Hi @Younes AITIFALI

    To answer your question: Yes.

    When you are creating an enterprise application (for external Identity Providers) you will be able to manage who can use the app by assigning users or groups to the application.

    226248-image.png

    Make Azure Active Directory an identity provider (with Okta as example)

    https://help.okta.com/en-us/Content/Topics/Provisioning/azure/azure-identify-identity-provider.htm#:~:text=Sign%20in%20to%20the%20Microsoft,left%20menu%20and%20click%20SAML.

    After adding Okta as an Azure AD Enterprise Application, assign certain users or groups (population) to the app and only they will be able to use Azure AD SSO.

    -----------------------

    If this is helpful please mark as correct answer.


  2. Mark Morowczynski 251 Reputation points Microsoft Employee
    2023-01-21T01:28:02.87+00:00

    When a domain name is federated, it's for ALL users that have that domain name. I suspect you do not want to change the domain name for some of the users. There is a thing called Stage Rollout [https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-staged-rollout which most people use to move OFF federation, But I suspect you could use it in the reverse to achieve your goal.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.