Ryno Posted January 9, 2015 Posted January 9, 2015 Hi all, is there any instructions on setting up adfs and sso? Also in education do you have to pay for azure or don't you need it? Last question is adfs the best route to go down? Thanks
Marshall_IT Posted January 9, 2015 Posted January 9, 2015 I don't think adfs is needed in school unless you absolutely want SSO internally for things like sharepoint etc. 1
Edu-IT Posted January 9, 2015 Posted January 9, 2015 Hi all, is there any instructions on setting up adfs and sso? Also in education do you have to pay for azure or don't you need it? Last question is adfs the best route to go down? Thanks What are you trying to setup SSO for?
Ryno Posted January 9, 2015 Author Posted January 9, 2015 I would like sso for Outlook as teachers have to go through the setup wizard on every computer they log in to as we do not have roaming profiles. - - - Updated - - - I would like sso for Outlook as teachers have to go through the setup wizard on every computer they log in to as we do not have roaming profiles.
EduTech Posted January 10, 2015 Posted January 10, 2015 Hi, Active Clients such as Outlook or Lync won't be using the passive endpoint on AD FS and so therefore what you want won't be possible. Your users will still need to enter a password because we use basic auth generally using the Microsoft Online Sign-In Assistant.. which is why today AAD Sync or (DirSync) would be a much better way for now in terms of ease of deployment. Saying that, we are making some major changes to how these clients authenticate by making use of the Azure Active Directory Authentication Library (ADAL) which will soon be what the Active Clients use for AuthN when this happens then AD FS will provide the same experience as the browser does today because it will use the passive endpoint. It seems that we have now made the announcement publicly to allow you to join the preview program and so i would recommend you read the following article for more information: Office 2013 updated authentication enabling Multi-Factor Authentication and SAML identity providers - Office Blogs If you have any further questions, let me know. Regards, James. 2
FN-GM Posted January 10, 2015 Posted January 10, 2015 (edited) Hi, Active Clients such as Outlook or Lync won't be using the passive endpoint on AD FS and so therefore what you want won't be possible. Your users will still need to enter a password because we use basic auth generally using the Microsoft Online Sign-In Assistant.. which is why today AAD Sync or (DirSync) would be a much better way for now in terms of ease of deployment. Saying that, we are making some major changes to how these clients authenticate by making use of the Azure Active Directory Authentication Library (ADAL) which will soon be what the Active Clients use for AuthN when this happens then AD FS will provide the same experience as the browser does today because it will use the passive endpoint. It seems that we have now made the announcement publicly to allow you to join the preview program and so i would recommend you read the following article for more information: Office 2013 updated authentication enabling Multi-Factor Authentication and SAML identity providers - Office Blogs If you have any further questions, let me know. Regards, James. You shouldn't need to enter a password for Lync 2013 with ADFS, it should work with SSO. I have setup quite a number of office 365 setups and every single one just worked with SSO out of the box. However good news about the changes, will help with outlook a great deal. @Ryno - You can auto configure outlook using group policy. See here - How to control Outlook AutoDiscover by using Group Policy Edited January 10, 2015 by FN-GM 1
Ryno Posted January 10, 2015 Author Posted January 10, 2015 So do you not think it will be worth spending time setting up ADFS ready for this update? Or is ADAL completely different? How much is azure for education?
EduTech Posted January 10, 2015 Posted January 10, 2015 So do you not think it will be worth spending time setting up ADFS ready for this update? Or is ADAL completely different? How much is azure for education? You do not need to use Microsoft Azure to host AD FS you can host the servers on-premise if you want to. Azure Active Directory as a Cloud Directory and is the Identity Platform that is used across all Microsoft Online Services. Azure AD is has 3 tiers (Free, Basic and Premium) and so by default if you sign up to any of the Microsoft Online Services such as Office 365, Intune, Dynamics CRM or RMS you get Azure AD Free. :-) ADAL is a new Authentication Library which is encouraged to be used by Develops whom want to use AAD as the iDP. The Office Clients as an example today use the Microsoft Online Sign-In Assistant, These will be moved over to use ADAL in due course. James. 1
Ryno Posted January 11, 2015 Author Posted January 11, 2015 Do you have a link where i can sign up to the free one? as i have tried signing up but i only got a trial of premium. Also with this will the staff passwords copy to office 365 so they don't have to use different passwords to login and then for their email?
EduTech Posted January 11, 2015 Posted January 11, 2015 Do you have a link where i can sign up to the free one? as i have tried signing up but i only got a trial of premium. Also with this will the staff passwords copy to office 365 so they don't have to use different passwords to login and then for their email? You get the FREE Azure AD Instance when you sign-up for a 1st Party Service such as Microsoft Office 365. In terms of Azure AD Premium Trial if you click on the Azure AD node in the management portal once you have your PAID Licenses or/ Education Licenses (i.e. no Trial) then it will give you access to the Azure Management Portal and then from here you will be able to Trial AAD Premium. You can purchase AAD Premium after the 90 Days via the Office 365 Portal If you wanted. If you use AADSync (Or if you already have DirSync) then you can enable Password Sync which will Sync User Passwords to AAD. James.
Ryno Posted January 13, 2015 Author Posted January 13, 2015 (edited) Can anyone help me with this? I have set up azure with dir sync and now it says "DOMAINS PLANNED FOR SINGLE SIGN-ON" 0. Thanks Edited January 13, 2015 by Ryno
InterwebsGuy Posted January 13, 2015 Posted January 13, 2015 Just to hijack this a little... We have an limited number of external IP addresses so we cannot run this on an internal server and publish to the web... I am looking at an alternative way of doing SSO for Google Apps, Moodle, and potentially some of the Office365 services down the road, as well as our on-site Remote Apps server. Currently we have a Moodle plugin that does SSO to Google Apps, and Moodle doing straight LDAP authentication. I'd prefer a centralized sign on point, that could SSO to all of these. I understand ADFS is the tool for this problem, but, I can't run it internally as it wouldn't be accessible externally. Has anyone had an experience of doing this with Azure? I assume, from my limited knowledge, we'd need to set up some kind of Azure AD then spin up an ADFS instance?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now