maniac Posted November 6, 2014 Posted November 6, 2014 I have a weird problem with the Onedrive for Business app that has only started recently. My Office 365 authentication uses the full ADFS setup which works brilliantly, I have no problems logging in on PC's or any other parts of the office 365 system EXCEPT the onedrive for business iOS app which for some reason recently has stopped working. I put my e-mail address into the login box in the app and click 'Sign in', the app redirects to my ADFS sign in page as expected, except it doesn't prompt for the password, it just errors straight away. The ADFS server logs an error code 364 when this happens "Encountered error during federation passive request." Most of the articles for this error suggest an issue with the time being out of sync across different servers, but I have checked all of these and they are all in-line with each other. (This would make sense seeing as the clocks went back at the weekend!) Has anyone got any ideas what might be causing this as I am drawing a blank when it comes to solving it. It was working fine at the start of the year, it has only started becoming an issue this week, but is causing me a problem as I'm trying to encourage office 365 use across the site and we have 1:1 student iPads so this app forms a cornerstone of my strategy so I need to get it working again! It's ADFS 3.0 on Server 2012 R2 by the way. Thanks in anticipation, Mike.
maniac Posted November 7, 2014 Author Posted November 7, 2014 (edited) OK well I've managed to find out what was causing this problem, however it has created another problem for me. Internally, our DNS server points our federation services address (https://fs.****academy.com) directly at our ADFS server to the outside world, this address is proxied by a Server 2012R2 web application proxy. This has allowed me to achieve single sign on to office 365 on our internal PC's by adding our domain to the intranet sites list so credentials are sent transparently when accessing the ADFS pages in a browser - this has been working a treat and continued to do so even when the sign in from the iOS apps stopped working. I discovered that signing into the apps worked at home, but not on premises and the only difference being the external access to ADFS goes through the web application proxy, so I changed our internal DNS rule to point at the WAP server instead of the ADFS server and lo and behold the apps started working again. HOWEVER - this has screwed up my SSO on the academy PC's which no longer works through the WAP server, and I can't find any way of making this work apart from pointing the DNS rule back at the ADFS server which fixes that, but breaks the iPad app sign in - I'm a bit trapped! Anyone got any ideas? Cheers, Mike. Edited November 7, 2014 by maniac
maniac Posted November 10, 2014 Author Posted November 10, 2014 I managed to fix this today. In short, I had only 'windows authentication' switched on for the intranet section of the global authentication policy. By switching on 'forms authentication' as well this got the iPad apps working internally again with the DNS rule pointing directly at the ADFS server. This means both my Single Sign on from PC's and the Apps now work again! Microsoft must have changed something in the latest release of the apps as the ADFS server has always had just windows authentication switched on and they were working just fine prior to the latest update for the app. Mike. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now