Re: Office 365 integration with hosted EZProxy for authentication using active directory?

Josh Welker <[email protected]>
Newsgroups gmane.education.ezproxy
Message-ID <CADYESeADdn1pg9bhX42qVbYo+1BGnKt4ZtneOyLWvy1zb3ZQPQ@mail.gmail.com>
There is a way to make this work. You can use EZproxy to authenticate
against just about anything if you can write an intermediary script. Have a
look at this documentation:

https://help.oclc.org/Library_Management/EZproxy/Authenticate_users/EZproxy_authentication_methods/External_script_authentication

Here's a potential flow:


   1. User fills out EZproxy login form and submits.
   2. EZproxy sends credentials to your script.
   3. Your script attempts to use those credentials to log in to Office 365
   via API.
   4. Your script sends back a message telling EZproxy if the login was
   valid or not.
   5. The user is now logged in (or not).

I agree with Robert that the unwillingness of the campus to use some sort
of network login is baffling. That's standard practice with EZproxy
everywhere I've seen.

Joshua Welker
Library Systems and Discovery Coordinator
James C. Kirkpatrick Library
University of Central Missouri
Warrensburg, MO 64093
JCKL 2260
660.543.8022



On Fri, Oct 11, 2019 at 11:20 AM Robert Rust <[email protected]> wrote:

> It should be noted that Microsoft is disabling Basic Authentication for
> their Office 365 services on October 13, 2020, so using IMAP auth with that
> service probably would fail after that.
>
>
>
> While I can understand a desire to restrict LDAP access, the restriction
> Tom’s campus has against ADFS (and perhaps related federated login
> solutions) is baffling to me. I would argue that maintaining logins
> manually is going to be less secure than relying on centrally managed
> credentials. We currently rely on Shibboleth, and as our institution’s Shib
> admin, I’m working on migrating other services utilizing LDAP connections
> to Shibboleth where possible (trying to keep ADFS minimized to just
> Microsoft services).
>
>
>
> -Robert
>
>
>
> *From: *EZproxy List <[email protected]> on behalf of "Ron S. Russ"
> <[email protected]>
> *Date: *Friday, October 11, 2019 at 9:44 AM
> *To: *"[email protected]" <[email protected]>
> *Subject: *Re: [EZPROXY-L] Office 365 integration with hosted EZProxy for
> authentication using active directory?
>
>
>
> *This Message is from a user outside of UW-River Falls*
>
> Tom,
>
>
>
> We’re looking into using Office365 with IMAP. So far, it has worked in the
> testing phase. We haven’t rolled it out publicly yet. We’re migrating to
> EZProxy hosted. Hope this helps.
>
>
>
> Ron
>
>
>
> Get Outlook for iOS
> <https://nam05.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2Fo0ukef&data=02%7C01%7Crobert.j.rust%40uwrf.edu%7C52834158b77143537fa408d74e59895c%7Cdbdf23c73f3a4bbeae76d7310a527fd8%7C1%7C1%7C637064018779862565&sdata=sAmKFQP%2FtqMBEqvpfThF%2BCR07F2NKPlBP7NpslL9eqU%3D&reserved=0>
> ------------------------------
>
> *From:* EZproxy List <[email protected]> on behalf of Craig, Tom <
> [email protected]>
> *Sent:* Thursday, October 10, 2019 2:41:46 PM
> *To:* [email protected] <[email protected]>
> *Subject:* [EZPROXY-L] Office 365 integration with hosted EZProxy for
> authentication using active directory?
>
>
>
> We use hosted EZProxy.  University security rules keep us from using LDAP,
> ADFS, etc., to authenticate users against our campus active directory, so I
> have to enter and manage EZProxy logins manually.  I have heard of various
> hosted systems such as an LMS being integrated somehow with Office 365 for
> authentication with active directory data.  If anyone does this or knows
> anything about this working with EZProxy and is willing to share, please
> contact me.  Thank you.
>
>
>
> Tom Craig, MSLS
> *Director of Library Services*
> Watson W. Wise Medical Research Library
>
> The University of Texas
> Health Science Center at Tyler
> 903.877.2864 office
>
> [image: The University of Texas Health Science Center Tyler]
>
>
>
>
>
>
>
>
> ------------------------------
>
> To unsubscribe from the EZPROXY-L list, click the following link:
> http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1
> <https://nam05.safelinks.protection.outlook.com/?url=http%3A%2F%2Flistserv.oclclists.org%2Fscripts%2Fwa.exe%3FSUBED1%3DEZPROXY-L%26A%3D1&data=02%7C01%7Crobert.j.rust%40uwrf.edu%7C52834158b77143537fa408d74e59895c%7Cdbdf23c73f3a4bbeae76d7310a527fd8%7C1%7C1%7C637064018779872559&sdata=502TcPCel%2BiVAwLjnoOP%2Bia8TkVH1BVp2id5G3XKOSA%3D&reserved=0>
>
>
> ------------------------------
>
> To unsubscribe from the EZPROXY-L list, click the following link:
> http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1
> <https://nam05.safelinks.protection.outlook.com/?url=http%3A%2F%2Flistserv.oclclists.org%2Fscripts%2Fwa.exe%3FSUBED1%3DEZPROXY-L%26A%3D1&data=02%7C01%7Crobert.j.rust%40uwrf.edu%7C52834158b77143537fa408d74e59895c%7Cdbdf23c73f3a4bbeae76d7310a527fd8%7C1%7C1%7C637064018779872559&sdata=502TcPCel%2BiVAwLjnoOP%2Bia8TkVH1BVp2id5G3XKOSA%3D&reserved=0>
>
> ------------------------------
>
> To unsubscribe from the EZPROXY-L list, click the following link:
> http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1
>


********************************************************************
If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences,
you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>.
Or email [email protected] including the relevant text below in the body of the email:
• To unsubscribe: "unsubscribe EZPROXY-L"
• To receive EZPROXY-L in digest form: "set EZPROXY-L digest"
• To set your options to no mail: "set EZPROXY-L nomail"
• To receive these messages in the future "set EZPROXY-L mail"
To contact the list owners directly please send your message to [email protected].
If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum.
To unsubscribe from all OCLC marketing email communications
(including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters),
please email us at [email protected].
image001.gif (image/gif, 5.5 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.