Hi,
I've been configuring Azure ACS for a SharePoint 2013 farm using this small step by step.
http://blah.winsmarts.com/2011-12-Integrate_Azure_ACS_with_SharePoint_in_2_minutes_or_less.aspx
First thing, it seems that the author made a mistake for the claim mapping, so i replaced "Email" by "EmailAddress". (i had an error message in Windows events saying something like "The trusted login provider did not supply a token accepted by this farm")
Once that fixed, i've been able to authentify via Google but not via live.
So I went to the rules groups (in ACS admin console) and changed the output claim type to emailaddress. (a weird thing, in incomming types i only have the choice of "nameidentifier").
Since then, I have no more error messages (including SharePoint logs) but loging in via Live leads to a "this site is not shared with you" message (but the autorization is set in people and groups).
Please find below the SAML token.
<wst:RequestSecurityTokenResponse xmlns:wst="http://schemas.xmlsoap.org/ws/2005/02/trust"><wst:RequestedSecurityToken><saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:1.0:assertion" AssertionID="uuid-b078262b-fcea-41af-88ca-c8b9f44f0b99" IssueInstant="2012-11-20T04:04:22Z" Issuer="uri:WindowsLiveID" MajorVersion="1" MinorVersion="1"><saml:Conditions NotBefore="2012-11-20T04:04:23Z" NotOnOrAfter="2012-11-20T12:04:23Z"><saml:AudienceRestrictionCondition><saml:Audience>accesscontrol.windows.net</saml:Audience></saml:AudienceRestrictionCondition></saml:Conditions><saml:AuthenticationStatement AuthenticationInstant="2012-11-19T23:08:01Z" AuthenticationMethod="urn:oasis:names:tc:SAML:1.0:am:password"><saml:Subject><saml:NameIdentifier Format="http://schemas.xmlsoap.org/claims/UPN">0006000008142BD63@Live.com</saml:NameIdentifier></saml:Subject></saml:AuthenticationStatement><saml:AttributeStatement><saml:Subject><saml:NameIdentifier Format="http://schemas.xmlsoap.org/claims/UPN">0006000008142BD63@Live.com</saml:NameIdentifier></saml:Subject><saml:Attribute AttributeName="Managed" AttributeNamespace="http://schemas.xmlsoap.org/claims"><saml:AttributeValue>TRUE</saml:AttributeValue></saml:Attribute><saml:Attribute AttributeName="Child" AttributeNamespace="http://schemas.xmlsoap.org/claims"><saml:AttributeValue>FALSE</saml:AttributeValue></saml:Attribute><saml:Attribute AttributeName="TOUAccepted" AttributeNamespace="http://schemas.xmlsoap.org/claims"><saml:AttributeValue>TRUE</saml:AttributeValue></saml:Attribute><saml:Attribute AttributeName="CID" AttributeNamespace="http://schemas.xmlsoap.org/claims"><saml:AttributeValue>dfe1cdd940359b2d</saml:AttributeValue></saml:Attribute><saml:Attribute AttributeName="EmailAddress" AttributeNamespace="http://schemas.xmlsoap.org/claims"><saml:AttributeValue>me@hotmail.com</saml:AttributeValue></saml:Attribute><saml:Attribute AttributeName="PUID" AttributeNamespace="http://schemas.xmlsoap.org/claims"><saml:AttributeValue>0006000008142BD63</saml:AttributeValue></saml:Attribute></saml:AttributeStatement><Signature xmlns="http://www.w3.org/2000/09/xmldsig#"><SignedInfo><CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"></CanonicalizationMethod><SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"></SignatureMethod><Reference URI="#uuid-b078262b-fcea-41af-88ca-c8b9f44f0b99"><Transforms><Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"></Transform><Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"></Transform></Transforms><DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"></DigestMethod><DigestValue>7DIBPHI9VhEdoyjgsImH827yono=</DigestValue></Reference></SignedInfo><SignatureValue>41kMRhSXDX7x8VENG8UUU4QvsnO84vgQ23caX2SysKY3eLQxjqwo92ClEvaa0Sa010dUCknyd7DBdbpz4w7eFSXNSltYaYoiHgH8ubzeHtaZjVKAKQKHHSCWzctAEC+R3mUj2PcPFNnQIZpds2pG+XoYSWPaj73TZ5hWXgsvXfc=</SignatureValue><KeyInfo><X509Data><X509SKI>H1D81qx0njcaeJ3fI6gkm6N/jpA=</X509SKI></X509Data><KeyName>Window Live ID</KeyName></KeyInfo></Signature></saml:Assertion></wst:RequestedSecurityToken><wsp:AppliesTo xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy"><wsa:EndpointReference xmlns:wsa="http://schemas.xmlsoap.org/ws/2004/08/addressing"><wsa:Address>http://accesscontrol.windows.net</wsa:Address></wsa:EndpointReference></wsp:AppliesTo></wst:RequestSecurityTokenResponse>
Thanks for helping!
PS: another thing that made my day in configuring ACS is this resource:
http://blogs.southworks.net/fboerr/2011/04/15/sliding-sessions-in-sharepoint-2010/
Cya