Jump to content

Recommended Posts

Posted

Hi all, is there any instructions on setting up adfs and sso? Also in education do you have to pay for azure or don't you need it? Last question is adfs the best route to go down?

 

Thanks

Posted
Hi all, is there any instructions on setting up adfs and sso? Also in education do you have to pay for azure or don't you need it? Last question is adfs the best route to go down?

 

Thanks

What are you trying to setup SSO for?

Posted

I would like sso for Outlook as teachers have to go through the setup wizard on every computer they log in to as we do not have roaming profiles.

 

- - - Updated - - -

 

I would like sso for Outlook as teachers have to go through the setup wizard on every computer they log in to as we do not have roaming profiles.

Posted

Hi,

 

Active Clients such as Outlook or Lync won't be using the passive endpoint on AD FS and so therefore what you want won't be possible. Your users will still need to enter a password because we use basic auth generally using the Microsoft Online Sign-In Assistant.. which is why today AAD Sync or (DirSync) would be a much better way for now in terms of ease of deployment.

 

Saying that, we are making some major changes to how these clients authenticate by making use of the Azure Active Directory Authentication Library (ADAL) which will soon be what the Active Clients use for AuthN when this happens then AD FS will provide the same experience as the browser does today because it will use the passive endpoint. It seems that we have now made the announcement publicly to allow you to join the preview program and so i would recommend you read the following article for more information: Office 2013 updated authentication enabling Multi-Factor Authentication and SAML identity providers - Office Blogs

 

If you have any further questions, let me know.

 

Regards,

James.

  • Thanks 2
Posted (edited)
Hi,

 

Active Clients such as Outlook or Lync won't be using the passive endpoint on AD FS and so therefore what you want won't be possible. Your users will still need to enter a password because we use basic auth generally using the Microsoft Online Sign-In Assistant.. which is why today AAD Sync or (DirSync) would be a much better way for now in terms of ease of deployment.

 

Saying that, we are making some major changes to how these clients authenticate by making use of the Azure Active Directory Authentication Library (ADAL) which will soon be what the Active Clients use for AuthN when this happens then AD FS will provide the same experience as the browser does today because it will use the passive endpoint. It seems that we have now made the announcement publicly to allow you to join the preview program and so i would recommend you read the following article for more information: Office 2013 updated authentication enabling Multi-Factor Authentication and SAML identity providers - Office Blogs

 

If you have any further questions, let me know.

 

Regards,

James.

 

You shouldn't need to enter a password for Lync 2013 with ADFS, it should work with SSO. I have setup quite a number of office 365 setups and every single one just worked with SSO out of the box. However good news about the changes, will help with outlook a great deal.

 

@Ryno - You can auto configure outlook using group policy. See here - How to control Outlook AutoDiscover by using Group Policy

Edited by FN-GM
  • Thanks 1
Posted
So do you not think it will be worth spending time setting up ADFS ready for this update? Or is ADAL completely different? How much is azure for education?
Posted
So do you not think it will be worth spending time setting up ADFS ready for this update? Or is ADAL completely different? How much is azure for education?

 

You do not need to use Microsoft Azure to host AD FS you can host the servers on-premise if you want to. Azure Active Directory as a Cloud Directory and is the Identity Platform that is used across all Microsoft Online Services. Azure AD is has 3 tiers (Free, Basic and Premium) and so by default if you sign up to any of the Microsoft Online Services such as Office 365, Intune, Dynamics CRM or RMS you get Azure AD Free. :-)

 

ADAL is a new Authentication Library which is encouraged to be used by Develops whom want to use AAD as the iDP. The Office Clients as an example today use the Microsoft Online Sign-In Assistant, These will be moved over to use ADAL in due course.

 

James.

  • Thanks 1
Posted
Do you have a link where i can sign up to the free one? as i have tried signing up but i only got a trial of premium. Also with this will the staff passwords copy to office 365 so they don't have to use different passwords to login and then for their email?
Posted
Do you have a link where i can sign up to the free one? as i have tried signing up but i only got a trial of premium. Also with this will the staff passwords copy to office 365 so they don't have to use different passwords to login and then for their email?

 

You get the FREE Azure AD Instance when you sign-up for a 1st Party Service such as Microsoft Office 365. In terms of Azure AD Premium Trial if you click on the Azure AD node in the management portal once you have your PAID Licenses or/ Education Licenses (i.e. no Trial) then it will give you access to the Azure Management Portal and then from here you will be able to Trial AAD Premium. You can purchase AAD Premium after the 90 Days via the Office 365 Portal If you wanted.

 

If you use AADSync (Or if you already have DirSync) then you can enable Password Sync which will Sync User Passwords to AAD.

 

James.

Posted (edited)

Can anyone help me with this? I have set up azure with dir sync and now it says "DOMAINS PLANNED FOR SINGLE SIGN-ON" 0.

 

azure.jpg

 

Thanks

Edited by Ryno
Posted

Just to hijack this a little...

We have an limited number of external IP addresses so we cannot run this on an internal server and publish to the web...

 

I am looking at an alternative way of doing SSO for Google Apps, Moodle, and potentially some of the Office365 services down the road, as well as our on-site Remote Apps server. Currently we have a Moodle plugin that does SSO to Google Apps, and Moodle doing straight LDAP authentication. I'd prefer a centralized sign on point, that could SSO to all of these. I understand ADFS is the tool for this problem, but, I can't run it internally as it wouldn't be accessible externally. Has anyone had an experience of doing this with Azure? I assume, from my limited knowledge, we'd need to set up some kind of Azure AD then spin up an ADFS instance?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...