@jason-johnson sagte in Support for Federated IDP:
Hello all
Is there any plan to support federated IDP systems? At my church, as it is non-profit, we receive the Microsoft grant for free email, Office 365 licenses and Azure credits. We would very much like to use ChurchTools for integration with things like Songbeamer, easier managing of teams across various church services and so on. But having to duplicate users, groups and so on in two systems is a non-starter. We also have no interest in having ChurchTools be the IDP because all our integrations come from Entra ID and will continue to do so (it was hard enough to get workers in the church to accept our MS accounts and Teams for communications).
I saw there is apparently some kind of LDAP integration but this is also problematic as Entra ID does not support LDAP. To make the connection requires settings up a special VLAN and a legacy Azure AD forest (this is strongly discouraged from MS as it's not very secure) which is configured to replicate from Entra ID. And all this just on the Microsoft side. I'm still not sure what I would need on the CT side to complete the configuration. In any case this is also not going to be a workable solution.
Our paster had a lot of experience using Churchtools from his previous church and has interest in this tool but without some way to use Entra ID as the IDP the IT team cannot support its usage.
2 Antworten Letzte Antwort 12. März 2025, 12:59
Antworten
I hear you. Federated IDP via Entra ID/SAML is a highly requested feature on our roadmap. For now, the LDAP connector is the only option, but we are actively evaluating modern SSO solutions.