University of Twente SAML 2.0 Identity Provider (SURFconext)
The university's own SAML 2.0 identity provider, entityID https://sts.windows.net/723246a1-c3f5-43c5-acdc-43adb404ac4d/, running on a Microsoft Entra ID tenant in the EU region and registered in SURFconext, the Dutch national research and education federation and an eduGAIN participant. The SURFconext IdP aggregate carries its EntityDescriptor with mdui:DisplayName "University of Twente" and the Shibboleth metadata extension shibmd:Scope regexp="false" utwente.nl, which is the federation asserting this IdP is authoritative for the utwente.nl scope. The tenant publishes its own SAML metadata and an OpenID Connect discovery document, both unauthenticated. A federation is shared by definition; the IdP behind it is the institution's, and this is the surface every gated UT service sits behind. The same tenant GUID appears independently in the canvas.utwente.nl login redirect and in the ctid of the Power BI report embedded on the university's own open-data page.