<?xml version="1.0" encoding="utf-8"?>
<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" ID="_599e5b08-004d-4ed0-9923-30d796bea0b6" entityID="https://idp1.netsferetest.com/273cb7d2-4144-43a6-b325-0d8e9891443b/">
  <RoleDescriptor xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:fed="http://docs.oasis-open.org/wsfed/federation/200706" xsi:type="fed:SecurityTokenServiceType" protocolSupportEnumeration="http://docs.oasis-open.org/wsfed/federation/200706">
    <KeyDescriptor use="signing">
      <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
        <X509Data>
          <X509Certificate>MIIDSTCCAjGgAwIBAgIUYQlR4RPHJAH2iw58rEkNE1eXNOQwDQYJKoZIhvcNAQELBQAwNDEyMDAGA1UEAwwpTWljcm9zb2Z0IEF6dXJlIEZlZGVyYXRlZCBTU08gQ2VydGlmaWNhdGUwHhcNMjUxMjA0MDUwMzQ5WhcNMjcxMjA0MDUwMzQ5WjA0MTIwMAYDVQQDDClNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKc+BsxFWUtg2czTirXueNjnqDPlz7v+OOcJyqgLnWlKYncCcGExPIZWRtPXeIl4OvuuUd1PySt70a7gISMzr3vpI7rBpELIs7TK8CYWds+VVsVZLLQ34jGJpsQnmgONFPje6MsmofUHVju1/suCMJwQHqJRE7JpxeqvuSkVRm09+w9q1KeuKIz9Byuv6MareElNMhEwlKlPQLqahGnBrwySTYacQQjzmb1z4FpmtPWoDRIkRI4kwuxLfQ3BrgqtVsO7znsytQpSPs+sP5+TuLetNaBfGbEQw2UGpP6DFL4IDOZ+0b91r7hvu99aTlr5+J1Qo3qHLWbDBeAnbaMCg78CAwEAAaNTMFEwHQYDVR0OBBYEFP3A2HVqZenOmIeU2SAK4ml0TrRlMB8GA1UdIwQYMBaAFP3A2HVqZenOmIeU2SAK4ml0TrRlMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJQGXEyxEdfXQCuBJLNi9NUa7FL8xUMxuTbZLTVbdSKw+vvJ46NSRi9yEO5C9I3gYNDtR6ZVl0tKWEPu8qhI3WX5ZLMB/GW9yGrU+07HeDXfqr18OitR0h9jotCZm2oN7WYYkoaf78ct3+Y84OyDzybude/gOz29AtPPpVchUNTbvQMSKQtEx6yYpNG3GmLIXELxK1eNj5Ic0otziL4rnCMbpw9M9STriCumsLrgA/0FhhAdPWH7yIlAlGRHYJOVDfBObmnp1HJux0gXstky7/H+pU1R34LG8VmEfyMEPLWS2xyH9m/bgKdt4bV8oX1LpYovHhMpu7eD9egA5a7aAv4=</X509Certificate>
        </X509Data>
      </KeyInfo>
    </KeyDescriptor>
    <fed:ClaimTypesOffered>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">
        <auth:DisplayName>Name</auth:DisplayName>
        <auth:Description>The mutable display name of the user.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier">
        <auth:DisplayName>Subject</auth:DisplayName>
        <auth:Description>An immutable, globally unique, non-reusable identifier of the user that is unique to the application for which a token is issued.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname">
        <auth:DisplayName>Given Name</auth:DisplayName>
        <auth:Description>First name of the user.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname">
        <auth:DisplayName>Surname</auth:DisplayName>
        <auth:Description>Last name of the user.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/identity/claims/displayname">
        <auth:DisplayName>Display Name</auth:DisplayName>
        <auth:Description>Display name of the user.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/identity/claims/nickname">
        <auth:DisplayName>Nick Name</auth:DisplayName>
        <auth:Description>Nick name of the user.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant">
        <auth:DisplayName>Authentication Instant</auth:DisplayName>
        <auth:Description>The time (UTC) when the user is authenticated to Windows Azure Active Directory.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod">
        <auth:DisplayName>Authentication Method</auth:DisplayName>
        <auth:Description>The method that Windows Azure Active Directory uses to authenticate users.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/identity/claims/objectidentifier">
        <auth:DisplayName>ObjectIdentifier</auth:DisplayName>
        <auth:Description>Primary identifier for the user in the directory. Immutable, globally unique, non-reusable.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/identity/claims/tenantid">
        <auth:DisplayName>TenantId</auth:DisplayName>
        <auth:Description>Identifier for the user's tenant.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/identity/claims/identityprovider">
        <auth:DisplayName>IdentityProvider</auth:DisplayName>
        <auth:Description>Identity provider for the user.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress">
        <auth:DisplayName>Email</auth:DisplayName>
        <auth:Description>Email address of the user.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups">
        <auth:DisplayName>Groups</auth:DisplayName>
        <auth:Description>Groups of the user.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/identity/claims/accesstoken">
        <auth:DisplayName>External Access Token</auth:DisplayName>
        <auth:Description>Access token issued by external identity provider.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/expiration">
        <auth:DisplayName>External Access Token Expiration</auth:DisplayName>
        <auth:Description>UTC expiration time of access token issued by external identity provider.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/identity/claims/openid2_id">
        <auth:DisplayName>External OpenID 2.0 Identifier</auth:DisplayName>
        <auth:Description>OpenID 2.0 identifier issued by external identity provider.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/claims/groups.link">
        <auth:DisplayName>GroupsOverageClaim</auth:DisplayName>
        <auth:Description>Issued when number of user's group claims exceeds return limit.</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/role">
        <auth:DisplayName>Role Claim</auth:DisplayName>
        <auth:Description>Roles that the user or Service Principal is attached to</auth:Description>
      </auth:ClaimType>
      <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/wids">
        <auth:DisplayName>RoleTemplate Id Claim</auth:DisplayName>
        <auth:Description>Role template id of the Built-in Directory Roles that the user is a member of</auth:Description>
      </auth:ClaimType>
    </fed:ClaimTypesOffered>
    <fed:SecurityTokenServiceEndpoint>
      <wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing">
        <wsa:Address>https://idp1.netsferetest.com/273cb7d2-4144-43a6-b325-0d8e9891443b/wsfed</wsa:Address>
      </wsa:EndpointReference>
    </fed:SecurityTokenServiceEndpoint>
    <fed:PassiveRequestorEndpoint>
      <wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing">
        <wsa:Address>https://idp1.netsferetest.com/273cb7d2-4144-43a6-b325-0d8e9891443b/wsfed</wsa:Address>
      </wsa:EndpointReference>
    </fed:PassiveRequestorEndpoint>
  </RoleDescriptor>
  <RoleDescriptor xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:fed="http://docs.oasis-open.org/wsfed/federation/200706" xsi:type="fed:ApplicationServiceType" protocolSupportEnumeration="http://docs.oasis-open.org/wsfed/federation/200706">
    <KeyDescriptor use="signing">
      <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
        <X509Data>
          <X509Certificate>MIIDSTCCAjGgAwIBAgIUYQlR4RPHJAH2iw58rEkNE1eXNOQwDQYJKoZIhvcNAQELBQAwNDEyMDAGA1UEAwwpTWljcm9zb2Z0IEF6dXJlIEZlZGVyYXRlZCBTU08gQ2VydGlmaWNhdGUwHhcNMjUxMjA0MDUwMzQ5WhcNMjcxMjA0MDUwMzQ5WjA0MTIwMAYDVQQDDClNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKc+BsxFWUtg2czTirXueNjnqDPlz7v+OOcJyqgLnWlKYncCcGExPIZWRtPXeIl4OvuuUd1PySt70a7gISMzr3vpI7rBpELIs7TK8CYWds+VVsVZLLQ34jGJpsQnmgONFPje6MsmofUHVju1/suCMJwQHqJRE7JpxeqvuSkVRm09+w9q1KeuKIz9Byuv6MareElNMhEwlKlPQLqahGnBrwySTYacQQjzmb1z4FpmtPWoDRIkRI4kwuxLfQ3BrgqtVsO7znsytQpSPs+sP5+TuLetNaBfGbEQw2UGpP6DFL4IDOZ+0b91r7hvu99aTlr5+J1Qo3qHLWbDBeAnbaMCg78CAwEAAaNTMFEwHQYDVR0OBBYEFP3A2HVqZenOmIeU2SAK4ml0TrRlMB8GA1UdIwQYMBaAFP3A2HVqZenOmIeU2SAK4ml0TrRlMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJQGXEyxEdfXQCuBJLNi9NUa7FL8xUMxuTbZLTVbdSKw+vvJ46NSRi9yEO5C9I3gYNDtR6ZVl0tKWEPu8qhI3WX5ZLMB/GW9yGrU+07HeDXfqr18OitR0h9jotCZm2oN7WYYkoaf78ct3+Y84OyDzybude/gOz29AtPPpVchUNTbvQMSKQtEx6yYpNG3GmLIXELxK1eNj5Ic0otziL4rnCMbpw9M9STriCumsLrgA/0FhhAdPWH7yIlAlGRHYJOVDfBObmnp1HJux0gXstky7/H+pU1R34LG8VmEfyMEPLWS2xyH9m/bgKdt4bV8oX1LpYovHhMpu7eD9egA5a7aAv4=</X509Certificate>
        </X509Data>
      </KeyInfo>
    </KeyDescriptor>
    <fed:TargetScopes>
      <wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing">
        <wsa:Address>https://sts.windows.net/273cb7d2-4144-43a6-b325-0d8e9891443b/</wsa:Address>
      </wsa:EndpointReference>
    </fed:TargetScopes>
    <fed:ApplicationServiceEndpoint>
      <wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing">
        <wsa:Address>https://idp1.netsferetest.com/273cb7d2-4144-43a6-b325-0d8e9891443b/wsfed</wsa:Address>
      </wsa:EndpointReference>
    </fed:ApplicationServiceEndpoint>
    <fed:PassiveRequestorEndpoint>
      <wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing">
        <wsa:Address>https://idp1.netsferetest.com/273cb7d2-4144-43a6-b325-0d8e9891443b/wsfed</wsa:Address>
      </wsa:EndpointReference>
    </fed:PassiveRequestorEndpoint>
  </RoleDescriptor>
  <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <KeyDescriptor use="signing">
      <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
        <X509Data>
          <X509Certificate>MIIDSTCCAjGgAwIBAgIUYQlR4RPHJAH2iw58rEkNE1eXNOQwDQYJKoZIhvcNAQELBQAwNDEyMDAGA1UEAwwpTWljcm9zb2Z0IEF6dXJlIEZlZGVyYXRlZCBTU08gQ2VydGlmaWNhdGUwHhcNMjUxMjA0MDUwMzQ5WhcNMjcxMjA0MDUwMzQ5WjA0MTIwMAYDVQQDDClNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKc+BsxFWUtg2czTirXueNjnqDPlz7v+OOcJyqgLnWlKYncCcGExPIZWRtPXeIl4OvuuUd1PySt70a7gISMzr3vpI7rBpELIs7TK8CYWds+VVsVZLLQ34jGJpsQnmgONFPje6MsmofUHVju1/suCMJwQHqJRE7JpxeqvuSkVRm09+w9q1KeuKIz9Byuv6MareElNMhEwlKlPQLqahGnBrwySTYacQQjzmb1z4FpmtPWoDRIkRI4kwuxLfQ3BrgqtVsO7znsytQpSPs+sP5+TuLetNaBfGbEQw2UGpP6DFL4IDOZ+0b91r7hvu99aTlr5+J1Qo3qHLWbDBeAnbaMCg78CAwEAAaNTMFEwHQYDVR0OBBYEFP3A2HVqZenOmIeU2SAK4ml0TrRlMB8GA1UdIwQYMBaAFP3A2HVqZenOmIeU2SAK4ml0TrRlMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJQGXEyxEdfXQCuBJLNi9NUa7FL8xUMxuTbZLTVbdSKw+vvJ46NSRi9yEO5C9I3gYNDtR6ZVl0tKWEPu8qhI3WX5ZLMB/GW9yGrU+07HeDXfqr18OitR0h9jotCZm2oN7WYYkoaf78ct3+Y84OyDzybude/gOz29AtPPpVchUNTbvQMSKQtEx6yYpNG3GmLIXELxK1eNj5Ic0otziL4rnCMbpw9M9STriCumsLrgA/0FhhAdPWH7yIlAlGRHYJOVDfBObmnp1HJux0gXstky7/H+pU1R34LG8VmEfyMEPLWS2xyH9m/bgKdt4bV8oX1LpYovHhMpu7eD9egA5a7aAv4=</X509Certificate>
        </X509Data>
      </KeyInfo>
    </KeyDescriptor>
    <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp1.netsferetest.com/273cb7d2-4144-43a6-b325-0d8e9891443b/saml2"/>
    <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp1.netsferetest.com/273cb7d2-4144-43a6-b325-0d8e9891443b/saml2"/>
    <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp1.netsferetest.com/273cb7d2-4144-43a6-b325-0d8e9891443b/saml2"/>
  </IDPSSODescriptor>
</EntityDescriptor>
