Jump to content

Recommended Posts

Posted
Would be nice to cut down on some of our vm's that are needed for SSO. Currently have 2 federated servers and 2 waps but as we have exchange hybrid and the phone system is linked, there is no point with me changing at the moment.
  • Thanks 1
Posted
I got it working last night. 1. make sure TCP9090 is allowed outbound from the machine you're running AAD Connect on, 2. make sure the two SSO URLs on the page OP linked are added to your Intranet Zone in IE. 3. I had to run the config two or three times for it to successfully update Office365 and our AD environment.
  • Thanks 1
Posted
I got it working last night. 1. make sure TCP9090 is allowed outbound from the machine you're running AAD Connect on, 2. make sure the two SSO URLs on the page OP linked are added to your Intranet Zone in IE. 3. I had to run the config two or three times for it to successfully update Office365 and our AD environment.

Can you set specific OUs to pass-through? It would be nice if student accounts could pass-through and staff accounts only password sync'd.

 

That way, theres no fear of staff who leave their machines unlocked, anyone could get to their emails without a password.

Posted
Can you set specific OUs to pass-through? It would be nice if student accounts could pass-through and staff accounts only password sync'd.

 

That way, theres no fear of staff who leave their machines unlocked, anyone could get to their emails without a password.

 

No, it's all or nothing on the AADConnect side. I suppose you could just not add the SSO URLs into the Intranet zone for staff users?

Posted (edited)

Before i configure AAD PTA.. i've currently got Password Sync selected. If i choose Pass-Through Authenitication and select Enable Single sign on user's passwords will still be sync'd so if tey are at home or access their accounts via a mobile they will still use their AD password?

 

I've searched the documentation and cannot see the 2 URLs to put in the trusted zone - either i'm being blind and dumb.

 

 

001.PNG

 

EDIT: I think ive found them.. are they: portal.office.com & outlook.office365.com? I might add mail.office365.com too.

Edited by timbo343
Posted

This is just a simpler way to have SSO than the current AD FS / WAP that we are all using, correct ?

 

I currently have AD FS / WAP working for SSO, this seems a simpler way but not worth doing for me as I already have the AD FS / WAP working well?

  • Thanks 1
  • 6 months later...
  • 2 weeks later...
Posted (edited)

So ive done as the article (https://marckean.com/2016/12/14/ad-connect-pass-through-authentication-sso) says but it doesnt auto log us into Office 365.

 

EDIT: Apologies, it seems things are working here. I didn't realise users has to put in there email address only (see this video https://marckean.com/2016/12/16/azuread-pass-through-authentication-and-seamless-single-sign-on-ux/)

Edited by timbo343

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...