Shibboleth

Service Providers (SPs) that use metadata to provide single sign-on access to a service may need to download and install a new signing certificate for U-M Federation Metadata and update the SP configuration with the new certificate and new URLs for the metadata.
This document is for U-M information technology staff members. It explains how to configure a Shibboleth Service Provider (SP) to use two-factor authentication, specifically for part of a service. This document builds on the information detailed in Configuring Your Shibboleth Service Provider for Two-Factor Authentication.
This document is for U-M information technology staff members. It details how to configure Shibboleth-enabled services to use two-factor authentication.
Note that Duo will be retired and all services must transition to using Okta for MFA by December 1, 2026. 
This document is for U-M information technology staff members. It provides basic instructions on installing the most recent Shibboleth Service Provider (SP) software (using the SAML protocol) on Windows Server and Internet Information Service (IIS) 7.x and above and configuring it for the U-M Identity Provider (IdP).
Shibboleth is used to allow members of the U-M community to log in to websites at other institutions that are members of the InCommon Federation using their uniqname and UMICH password. It is also used to enable web login to U-M Google, U-M Dropbox, and other cloud-based services used at the university.
This document describes how to log out of a service that uses U-M’s Weblogin single sign-on service (Shibboleth)
This document provides the resources necessary for setting up a Shibboleth Service Provider (SP). Request Form and Windows ConfigurationIf your department or unit has a web resource that you wish to offer to people at another institution, ask your departmental or unit IT staff to fill out the Shibboleth Configuration Request form.
This document is intended for U-M IT staff. It  (1) Provides brief background information about federated identity management, InCommon, Shibboleth and attributes; (2) Describes the procedure for requesting that U-M release attributes to a Shibboleth Service Provider (SP) to permit access to U-M users; (3) Provides detailed information about the attributes available to SPs; and (4) Details the general procedure for reviewing and approving attribute release.
This document is for U-M information technology staff members. It provides basic instructions on updating the /etc/hosts file to test a Service Provider (SP) application against the new Shibboleth environment.