Tec de Monterrey AD FS Identity Provider (fs.itesm.mx)
The institution's own SAML 2.0 / WS-Federation / OpenID Connect identity provider, on its own registrable domain itesm.mx. Signed SAML metadata is served at the standard AD FS path with Content-Type application/samlmetadata+xml and entityID http://fs.itesm.mx/adfs/services/trust; an OpenID Connect discovery document is served at /adfs/.well-known/openid-configuration with issuer https://fs.itesm.mx/adfs. Microsoft's getuserrealm service names this host as the authoritative AuthURL for both tec.mx and itesm.mx, confirming it is the institution's primary IdP rather than a vendor's. This is the strongest machine-readable surface the institution operates and it is fully open — no credential is needed to read the metadata.