Jump to content

Recommended Posts

Posted

I have adfs 3.0 and managed to federate the domain. However SSO isn't working as i think there is another step which is to install "Azure AD Connect"

 

If i install and set it up, will the usernames change? i.e from jbloggs to [email protected]?

 

I am concerned about this bit:

 

Depending on each of your domains, you may need to do the following:

The UPN must be set and known by the user.

 

The UPN domain suffix must be under the domain that you choose to set up for single sign-on.

Posted

so to make SSO work they need to authenticate as [email protected] on the domain, and this allows login to o365. Can it work with domain\jbloggs instead?

 

If not, how did you tell the users that the username is going to change?

Posted

I've not done SSO myself but I don't think you need to change the Login names locally. Just the upn needs to be the same.

 

So I'd the currently log on as domain.ac.uk\jbloggs locally, their login name on office 365 need to be [email protected]

 

I was using domain.local and i had to add my public domain as an extra domain to ad.

  • Thanks 1
Posted

Add your external domain(s) as additional UPN suffixes in AD Domains & Trusts

Capture.PNG

Then you need to set all of your users to use the correct UPN Suffix.

 

You will still get prompted for an email address/password if you are using anything other than internet explorer, Office on a domain PC.

  • Thanks 1
Posted (edited)

By adding the UPN suffixes in AD Domains & Trusts, does that mean they can continue with the existing login usernames and the sch.uk bit is auto added in the background or do they need to type the whole thing in?

 

Also is the azure AD connect tool installed on the DC / WAP / or a separate server?

Edited by win
Posted

Yep that is correct, it uses the same username and password, just has the additional bits added to the end. In my case, I can log on with [email protected], or [email protected]al, or crick\nick.

 

I have mine installed on our web server for the ADFS stuff, I think I migrated it from the 2nd DC when I was enabling ADFS (switched from DirSync as well)

  • Thanks 1
Posted
I read somewhere that the new AD connect tool (just released) shouldn't be installed on a DC so i made another server and will install the tool later. Seems like a lot of servers are needed to make o365 to work, thought cloud was supposed to make things simpler!
Posted
If the server ad connect sits on is rebooted, what will the effect be? Does it only sync at specified intervals?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...