> For the complete documentation index, see [llms.txt](https://ajuda.rnp.br/cafe/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajuda.rnp.br/cafe/idp-cafe/faq/integrando-o-office-365-com-shibboleth-idp/office-365-configuracao-no-shibbboleth-idp.md).

# Office 365 - Configuração no Shibbboleth IDP

Durante essa etapa serão manipulados os seguintes arquivos:

* /opt/shibboleth-idp/conf/relying-party.xml
* /opt/shibboleth-idp/conf/saml-nameid.xml
* /opt/shibboleth-idp/conf/attribute-resolver.xml
* /opt/shibboleth-idp/conf/attributes/custom/ImmutableID.properties
* /opt/shibboleth-idp/conf/attributes/custom/UserId.properties
* /opt/shibboleth-idp/conf/metadata-providers.xml
* /opt/shibboleth-idp/metadata/office365-md.xml
* /opt/shibboleth-idp/conf/attribute-filter.xml

{% hint style="danger" %}
É fortemente recomendada a realização de backup do IDP antes de executar esse procedimento
{% endhint %}

No arquivo `/opt/shibboleth-idp/conf/relying-party.xml`, sob o item `<util:list id="shibboleth.RelyingPartyOverrides">`, adicione a configuração abaixo:

```xml
<bean id="Office365" parent="RelyingPartyByName" c:relyingPartyIds="urn:federation:MicrosoftOnline">
   <property name="profileConfigurations">
      <list>
         <bean parent="SAML2.SSO" p:encryptAssertions="false" p:signAssertions="true" p:signResponses="false" />
         <bean parent="SAML2.ECP" p:encryptAssertions="false" p:signAssertions="true" p:signResponses="false" p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" />
      </list>
   </property>
</bean>
```

Já no arquivo `/opt/shibboleth-idp/conf/saml-nameid.xml`, dentro do item `<util:list id="shibboleth.SAML2NameIDGenerators">`, adicione a configuração abaixo:

```xml
<!-- CAFe- Persistent NameID -->
<bean parent="shibboleth.SAML2PersistentGenerator">
   <property name="activationCondition">
      <bean parent="shibboleth.Conditions.NOT">
         <constructor-arg>
            <bean parent="shibboleth.Conditions.RelyingPartyId" c:candidate="urn:federation:MicrosoftOnline" />
         </constructor-arg>
      </bean>
   </property>
</bean>

<!-- CAFe - Persistent NameID exclusivo para Microsoft -->
<bean parent="shibboleth.SAML2AttributeSourcedGenerator"
      p:omitQualifiers="true"
      p:format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
      p:attributeSourceIds="#{ {'ImmutableID'} }">
   <property name="activationCondition">
      <bean parent="shibboleth.Conditions.RelyingPartyId" c:candidate="urn:federation:MicrosoftOnline" />
   </property>
</bean>
```

Para criar os atribututos que serão usados (`ImmutableID` e `UserId`), altere o arquivo `/opt/shibboleth-idp/conf/attribute-resolver.xml` adicionando as linhas a seguir:

```xml
<!-- CAFe - ImmutableID para Microsoft -->
<AttributeDefinition xsi:type="Simple" id="ImmutableID">
   <InputDataConnector ref="dcLDAP" attributeNames="entryUUID"/>
</AttributeDefinition>

<!-- CAFe - UserId para Microsoft -->
<AttributeDefinition scope="%{idp.scope}" xsi:type="Scoped" id="UserId">
   <InputDataConnector ref="dcLDAP" attributeNames="uid"/>
 </AttributeDefinition>
```

Ainda no arquivo `/opt/shibboleth-idp/conf/attribute-resolver.xml`, adicione o atributo `entryUUID` à lista de atributos retornaveis do dataconnector `dcLDAP`. Exemplo:

```xml
<ReturnAttributes>%{idp.authn.LDAP.returnAttributes} mail cn givenName sn brPersonCPF schacDateOfBirth entryUUID</ReturnAttributes>
```

{% hint style="warning" %}
O uso dos atributos **`entryUUID`** e **`uid`** é apropriado para ambientes **OpenLDAP**. Caso esteja utilizando outro diretório deve-se substituí-los pelos atributos correspondentes. Ex.: **AD** - **entryUUID > objectGUID** e **uid > sAMAccountName**.
{% endhint %}

Crie o arquivo `/opt/shibboleth-idp/conf/attributes/custom/ImmutableID.properties` com o seguinte conteúdo:

```properties
# Microsoft Entra ImmutableID

id=ImmutableID
transcoder=SAML2StringTranscoder
displayName.en=Microsoft Entra ImmutableID
displayName.pt-br=Microsoft Entra ImmutableID
description.en=Microsoft Entra ImmutableID
description.pt-br=Microsoft Entra ImmutableID
saml2.name=urn:oid:1.2.840.113556.1.4.2
saml1.encodeType=false
```

Crie o arquivo `/opt/shibboleth-idp/conf/attributes/custom/UserId.properties` com o seguinte conteúdo:

```properties
# Microsoft Entra User ID

id=UserId
transcoder=SAML2ScopedStringTranscoder
displayName.en=Microsoft Entra User ID
displayName.pt-br=Microsoft Entra User ID
description.en=Microsoft Entra User ID
description.pt-br=Microsoft Entra User ID
saml2.name=urn:oid:0.9.2342.19200300.100.1.1
saml1.encodeType=false
```

Para configurar o provedor de metadados, altere o arquivo `/opt/shibboleth-idp/conf/metadata-providers.xml` e adicione a configuração abaixo:

```xml
<MetadataProvider id="Office365" xsi:type="FilesystemMetadataProvider" metadataFile="%{idp.home}/metadata/microsoft-md.xml"/>
```

A seguir baixe o arquivo de metadados da Microsoft e armazene-o no local apropriado e remova a linha `<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>`.

```bash
wget https://nexus.microsoftonline-p.com/federationmetadata/saml20/federationmetadata.xml -O /opt/shibboleth-idp/metadata/microsoft-md.xml
```

Por fim, altere o arquivo `/opt/shibboleth-idp/conf/attribute-filter.xml` incluindo a política de liberação de atributos para o Microsoft Entra.

```xml
<AttributeFilterPolicy id="PolicyForMicrosoftEntra">
   <PolicyRequirementRule xsi:type="Requester" value="urn:federation:MicrosoftOnline" />
   
   <AttributeRule attributeID="UserId">
      <PermitValueRule xsi:type="ANY"/>
   </AttributeRule>
   
   <AttributeRule attributeID="ImmutableID">
      <PermitValueRule xsi:type="ANY"/>
   </AttributeRule>

</AttributeFilterPolicy>
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajuda.rnp.br/cafe/idp-cafe/faq/integrando-o-office-365-com-shibboleth-idp/office-365-configuracao-no-shibbboleth-idp.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
