Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_tools
powershell_heavy
windows_first
missing_linux_example
Summary
The documentation demonstrates a strong Windows bias. All administrative steps for configuring AD FS are described using Windows-specific tools such as Server Manager, AD FS Management snap-in, Event Viewer, and PowerShell cmdlets. There are no Linux equivalents or cross-platform alternatives provided, and all examples and troubleshooting steps assume a Windows environment. Linux-based AD FS alternatives or SAML identity providers are not mentioned.
Recommendations
  • Provide guidance or references for configuring SAML identity providers on Linux (e.g., Shibboleth, SimpleSAMLphp) as alternatives to AD FS.
  • Include example commands or steps for managing certificates and SAML metadata using cross-platform tools (e.g., OpenSSL for certificate creation, curl/wget for metadata retrieval).
  • When referencing PowerShell or Windows-specific tools, add equivalent commands or instructions for Linux environments where possible.
  • Clarify at the beginning that the guide is Windows/AD FS-specific, and link to documentation for Linux-based SAML providers if full parity is not feasible.
  • Add troubleshooting steps that are relevant for Linux-based SAML providers, such as checking logs or configuration files.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Biased Biased
2026-01-11 00:00 #95 cancelled Clean Clean
2026-01-10 00:00 #92 completed Clean Clean
2026-01-09 00:00 #87 cancelled Clean Clean
2026-01-08 00:00 #84 in_progress Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2026-01-06 18:40 #75 cancelled Biased Biased
2025-12-29 18:00 #48 cancelled Clean Clean
2025-12-22 00:00 #24 cancelled Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean

Flagged Code Snippets

    <ClaimsProvider>
      <Domain>contoso.com</Domain>
      <DisplayName>Contoso</DisplayName>
      <TechnicalProfiles>
        <TechnicalProfile Id="Contoso-SAML2">
          <DisplayName>Contoso</DisplayName>
          <Description>Login with your AD FS account</Description>
          <Protocol Name="SAML2"/>
          <Metadata>
            <Item Key="WantsEncryptedAssertions">false</Item>
            <Item Key="PartnerEntity">https://your-AD-FS-domain/federationmetadata/2007-06/federationmetadata.xml</Item>
          </Metadata>
          <CryptographicKeys>
            <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SAMLSigningCert"/>
          </CryptographicKeys>
          <OutputClaims>
            <OutputClaim ClaimTypeReferenceId="issuerUserId" PartnerClaimType="userPrincipalName" />
            <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="given_name"/>
            <OutputClaim ClaimTypeReferenceId="surname" PartnerClaimType="family_name"/>
            <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="email"/>
            <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="name"/>
            <OutputClaim ClaimTypeReferenceId="identityProvider" DefaultValue="contoso.com" />
            <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="socialIdpAuthentication"/>
          </OutputClaims>
          <OutputClaimsTransformations>
            <OutputClaimsTransformation ReferenceId="CreateRandomUPNUserName"/>
            <OutputClaimsTransformation ReferenceId="CreateUserPrincipalName"/>
            <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId"/>
            <OutputClaimsTransformation ReferenceId="CreateSubjectClaimFromAlternativeSecurityId"/>
          </OutputClaimsTransformations>
          <UseTechnicalProfileForSessionManagement ReferenceId="SM-Saml-idp"/>
        </TechnicalProfile>
      </TechnicalProfiles>
    </ClaimsProvider>
    
<Metadata>
  <Item Key="WantsEncryptedAssertions">false</Item>
  <Item Key="PartnerEntity">https://your-AD-FS-domain/federationmetadata/2007-06/federationmetadata.xml</Item>
  <Item Key="XmlSignatureAlgorithm">Sha256</Item>
</Metadata>
<Metadata>
  <Item Key="WantsEncryptedAssertions">false</Item>
  <Item Key="PartnerEntity">https://your-AD-FS-domain/federationmetadata/2007-06/federationmetadata.xml</Item>
  <Item Key="ResponsesSigned">false</Item>
</Metadata>