Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

That’s an important observation: The IDPEmail attribute is an identifier, and moreover, it is actually used by the Office 365 application for access control. That leads directly to our next observation. 

Tip
titleLesson Learned #2
All user identifiers must be scope-checked by the relying party.