Skip to main content

Cooperative Authentication

Enables applications that are configured to use Web SSO to utilize either a Shibboleth or Entra ID authentication token. By allowing Web SSO to use tokens from both sources, login prompts are minimized and the authentication experience enhanced. Those that adopt SDES or are using a managed OSUWMC device will experience a true Single Sign On experience by being able to leverage authentication tokens from their Windows sign in.

Authentication behavior when a person accesses an authorized application if they are an OSU employee, student or guest:

Starting Authentication StateApp connected to Shibboleth ProxyApp connected to ShibbolethApp connected to M365
Not AuthenticatedM365 Login PromptShibboleth Login PromptM365 Login Prompt
Authenticated to ShibbolethNo prompt, allowed to accessNo prompt, allowed to accessM365 Login Prompt
Authenticated to M365No prompt, allowed to accessShibboleth Login PromptNo prompt, allowed to access
Authenticate to SDES or OSUWMC managed deviceNo prompt, allowed to accessShibboleth Login PromptNo prompt, allowed to access

What about a Medical Center person? It works the same! OSUWMC Person uses their OSUWMC M365 authentication token.

Current Authentication state
With Cooperative Authentication flow

Additional Resources

Cooperative Authentication FAQ

Login Experience

To see what the user will experience in an environment enabled for Cooperative Authentication please see:

Important Information