Jump to content

Recommended Posts

Posted

Thanks @EduTech

 

Im going to see if we can dump some stuff that we use in Outlook and isn't in OWA.

 

Do your users have to login to SIMS each time, or have you tied that to AD? If not, it's the same sort of thing.

 

Tired into AD like our other services.

Posted
Just out of interest, do you have to run Internet Explorer before opening Outlook for first time in order for Office 365 account to be setup automatically? That's what I experience. Not too troublesome but curious if you have same issue. I wonder if it's something to do with our web filter needing a connection from IE to establish the user and policy etc.
Posted
Just out of interest, do you have to run Internet Explorer before opening Outlook for first time in order for Office 365 account to be setup automatically? That's what I experience. Not too troublesome but curious if you have same issue. I wonder if it's something to do with our web filter needing a connection from IE to establish the user and policy etc.

 

Hi Mate, @Edu-IT

 

If that is the experience you have, this is caused because the Web Proxy I assume you are going through requires authentication, in this scenario outlook is not able to negotiate the authentication and so therefore this is why you have to launch Internet Explorer first so that it authenticates against your Web Proxy which then allows outlook to get out on the internet etc.

 

Generally, If your machines can go direct to the internet without the proxy then you would add this into an exception list and so that it can break out directly without going over the web proxy but that will depend on your infrastructure.

 

in essence, outlook is unable to negotiate the authentication mechanism required by your web application proxy in order to access the internet and so hence it fails to connect until you launch a browser to handle that aspect for you.

 

Hope that helps,

James.

Posted
What URL will it be going out to as I'm confident they're excluded. I suspected it was a filtering auth issue so you've just confirmed that. I suppose I could dive into the logs to see where it's trying to go.
Posted

I believe it will be contacting "outlook.office365.com"

 

This is the latest list as of 27/05

 

*.aadrm.com

*.activedirectory.windowsazure.com

*.glbdns.microsoft.com

*.live.com

*.lync.com

*.microsoft.com

*.microsoftonline.com

*.microsoftonline-p.com

*.microsoftonline-p.net

*.microsoftonlineimages.com

*.microsoftonlinesupport.net¹

*.msecnd.net

*.msocdn.com

*.msn.com

*.msn.co.jp

*.msn.co.uk

*.onmicrosoft.com

*.office.com

*.office.net

*.office365.com

*.officeapps.live.com

*.outlook.com

*.phonefactor.net

*.Sharepoint.com

*.Sharepointonline.com

 

Article Here: Office 365 URLs and IP address ranges

 

James.

Posted
Just out of interest, do you have to run Internet Explorer before opening Outlook for first time in order for Office 365 account to be setup automatically? That's what I experience. Not too troublesome but curious if you have same issue. I wonder if it's something to do with our web filter needing a connection from IE to establish the user and policy etc.

 

Nope, we have made it as an authentication exception as @EduTech suggests.

Posted
I believe it will be contacting "outlook.office365.com"

 

This is the latest list as of 27/05

 

*.aadrm.com

*.activedirectory.windowsazure.com

*.glbdns.microsoft.com

*.live.com

*.lync.com

*.microsoft.com

*.microsoftonline.com

*.microsoftonline-p.com

*.microsoftonline-p.net

*.microsoftonlineimages.com

*.microsoftonlinesupport.net¹

*.msecnd.net

*.msocdn.com

*.msn.com

*.msn.co.jp

*.msn.co.uk

*.onmicrosoft.com

*.office.com

*.office.net

*.office365.com

*.officeapps.live.com

*.outlook.com

*.phonefactor.net

*.Sharepoint.com

*.Sharepointonline.com

 

Article Here: Office 365 URLs and IP address ranges

 

James.

 

While not directly relevent, anybody who's whitelisted the IP's for a proxy should take note of the notice posted in the Admin Center saying that some of them will be changing very soon.

Posted
Really if it can be done with on premise it can be done with with 365 (obviously some work from MS is required).

 

It's not as straightforward as you might think. :)

 

For what it's worth, you might want to look at password sync as an alternative to ADFS if you're not getting the scenario you want. Maintaining a reliable and robust ADFS infrastructure when it's not delivering SSO 100% of the time could be overkill, whereas password sync gives you "consistent" sign-on which doesn't need you to have highly available servers.

 

(I know I've linked to this many times in various threads, but it's still pretty accurate: Deploying Office 365 Education? You don't need single sign-on, and here's why!)

  • 2 weeks later...
Posted
I feel this post is better here, rather than start a new topic, but has anyone managed to set this up as part of an admin file for Office 2013? I.e. Can we set up a basic profile for Outlook 2013 to ease our students connecting to O365? We're likely to be deploying Win8.1 with Office 2013 and I'd like to give a helping 'nudge' where possible.
  • 1 month later...
Posted
Got some news on this. Apparently they are changing how this authentication works so one day it will be SSO. Not sure when though!
  • Thanks 1
Posted
Got some news on this. Apparently they are changing how this authentication works so one day it will be SSO. Not sure when though!

What is the source of this news and what have you been told? We've moved to office365 but feel the outlook use is a backward step compared to an onsite exchange box that we did have.

 

Pete

Posted
What is the source of this news and what have you been told? We've moved to office365 but feel the outlook use is a backward step compared to an onsite exchange box that we did have.

 

Pete

 

Glad someone feels the same way I do!

 

I was told this by an escalations engineer at Microsoft Technical Support.

  • 4 months later...
Posted
Glad someone feels the same way I do!

 

I was told this by an escalations engineer at Microsoft Technical Support.

 

Just looking into ADFS and Outlook 2013. Did you get anymore updates from Microsoft about this issue?

Posted
Just looking into ADFS and Outlook 2013. Did you get anymore updates from Microsoft about this issue?

 

According to the these links that they are setting up MAPI over HTTP for Office 365. "A huge architectural improvement by moving to MAPI/HTTP is that MAPI/HTTP is abstracted from authentication. In short authentication is done at the HTTP layer, so whatever HTTP can do, MAPI/HTTP can use."

 

This suggests they are setting up SSO for Outlook and Exchange Online. SSO is currently performed over HTTP with OWA. There was another site somewhere that put more light onto the subject but i cannot find it at the moment.

 

Office 365 Roadmap

Outlook Connectivity with MAPI over HTTP - Exchange Team Blog - Site Home - TechNet Blogs

  • Thanks 1
Posted
The benefit of having Office 365 outweigh having to enter password, surely?

 

I second this... Granted I haft to spend about 10 minutes every two months (Telling one or two people to type there new password in) when the password cycle expires.

 

But 10 minutes of my time for no more exchange server or worries...... I would take that deal 1 million times over!

Posted

Folks,

 

Keep an eye out on the blog for updates in regards to this, we currently have this in a controlled private preview release where we are allowing customers to test this with our support and have done for some time now. We are already starting to move over the Mobile Applications etc. to use the new Azure AD Authentication Library and so just watch this space.

 

Office 2013 updated authentication enabling Multi-Factor Authentication and SAML identity providers - Office Blogs

 

Thanks,

James.

  • Thanks 1
Posted
Folks,

 

Keep an eye out on the blog for updates in regards to this, we currently have this in a controlled private preview release where we are allowing customers to test this with our support and have done for some time now. We are already starting to move over the Mobile Applications etc. to use the new Azure AD Authentication Library and so just watch this space.

 

Office 2013 updated authentication enabling Multi-Factor Authentication and SAML identity providers - Office Blogs

 

Thanks,

James.

 

Excellent news @EduTech ! Do we know when us normal folk can get it please?

  • 4 months later...
Posted
Folks,

 

Keep an eye out on the blog for updates in regards to this, we currently have this in a controlled private preview release where we are allowing customers to test this with our support and have done for some time now. We are already starting to move over the Mobile Applications etc. to use the new Azure AD Authentication Library and so just watch this space.

 

Office 2013 updated authentication enabling Multi-Factor Authentication and SAML identity providers - Office Blogs

 

Thanks,

James.

 

Hi James / @EduTech - I am just wondering if we have any updates with progress with this please?

 

Thanks

Posted
Hi James / @EduTech - I am just wondering if we have any updates with progress with this please?

 

Thanks

 

Have you signed up for the Public Preview? If you send me your TenantID (*.onmicrosoft.com) I can check this out for you.

 

Thanks,

James.

Posted
Have you signed up for the Public Preview? If you send me your TenantID (*.onmicrosoft.com) I can check this out for you.

 

Thanks,

James.

 

Hi @EduTech We haven't no, Im just not sure about putting this into production, don't want to interrupt service if its not ready for general release. Do we know when it will be ready for general release please?

 

thanks

Posted
Hi @EduTech We haven't no, Im just not sure about putting this into production, don't want to interrupt service if its not ready for general release. Do we know when it will be ready for general release please?

 

thanks

 

In which case then it's not going to work, if you have it enabled it's only activated via the registry anyway so it wouldn't cause any issues with production. I cant give you a date as to when this will be GA.

 

Thanks,

James.

Posted
In which case then it's not going to work, if you have it enabled it's only activated via the registry anyway so it wouldn't cause any issues with production. I cant give you a date as to when this will be GA.

 

Thanks,

James.

 

I assume you activate it via Office 365 as well? So I won't be able to simply turn it off?

 

Thanks

Posted

We have joined the public preview and I can confirm that users no longer need to sign in to Outlook, silent SSO occurs from our ADFS server (2012 R2). Just a heads up though, it didn't work "out of the box", initially everyone received a forms authentication window from the ADFS rather than the basic authentication dialog. By chance we came across a blog post here that indicated we did not have an ADFS endpoint enabled. After running the Powershell command mentioned in the article SSO started working.

 

Once this is enabled on your tenancy you can enable/disable it on each client via registry keys so you shouldn't need to worry about turning it off globally.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...