Thanks Ray,

I can set both the entity id and keys in each tenant.
If I understand correctly, you suggest that I use the same entityID and key 
between each tenant but add a <md:AssertionConsumerService ... /> line to 
the "common metadata".
No matter which tenant they hit, my IdP will see the request as if it came 
from a single SP.

I thought the ACS had something to do with redirecting the user back to the 
SP. How does that work when you have more than one?


On Thursday, April 23, 2026 at 7:55:57 PM UTC-4 Ray Bon wrote:

> Jeremiah,
>
> SAML services do not have the concept of regular expression matching 
> entityID.
>
> Are you able to set the entityID and encryption key in workday SAML 
> config? 
>
> Each tenant will have a unique AssertionConsumerService. If you maintain 
> the metadata locally, you can have multiple ACS stanzas.
>
> Combining tenants like this will prevent you from creating a separation of 
> concerns in your user base since authn decisions are made on the entityID.
>
> Ray
>
> ------------------------------
> *From:* 'Jeremiah Garmatter' via CAS Community <[email protected]>
> *Sent:* April 23, 2026 13:13
> *To:* CAS Community <[email protected]>
> *Subject:* [cas-user] Condensing multiple SSO integrations? 
>  
> Hello,
>
> My organization is migrating to a product called Workday.
> This product encourages you to spin up different "tenants" (instances) of 
> the product.
> Unfortunately, each of these tenants requires a separate SAML integration.
> Is there some way I could condense them into one integration?
> The metadata is nearly identical between them. There may be a different 
> key and the URLS may differ in a small portion of the path, otherwise they 
> are the same.
> To be honest, I'm not sure what a feature like this would look like but if 
> anyone has ideas I'm open to suggestions. CAS 7.3.1, SAML integrations.
>
> -- 
> - Website: https://apereo.github.io/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> --- 
> You received this message because you are subscribed to the Google Groups 
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected].
> To view this discussion visit 
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/fb0b3db3-2624-4870-a7e5-d2955e74b06cn%40apereo.org
>  
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/fb0b3db3-2624-4870-a7e5-d2955e74b06cn%40apereo.org?utm_medium=email&utm_source=footer>
> .
>

-- 
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/3d880443-9d85-4280-9214-51d657f7a95an%40apereo.org.

Reply via email to