snagrat Posted August 6, 2017 Posted August 6, 2017 I've got unlimited license for Office365 Edu Pro Plus on our Office365 account - I thought all schools got this? I certainly haven't done anything to link our volume licensing account and Office365 tenant - surely MS weren't *that* on the ball If the email domain on the VL agreement is verified in Office 365, and you license Office via VL, then Microsoft seem to match the two together and give the ProPlus licenses. Doesn't always happen automatically though
Tefters Posted August 7, 2017 Posted August 7, 2017 (edited) You don't need the Office 365 CTR for SSO to work with Office 365 logins, I currently have Office 365 Pro Plus on a Windows 10 1607 image with Office 365 SSO working absolutely fine through an ADFS server and then a WAP server for extra DMZ security. Last time I looked and tested this was Thursday last week. EDIT - To also help people on the licensing confusion. Office 2016/Pro Plus are for installation on school devices and hopefully you purchased the licensing through your ESS agreement. Office 2016 CTR through Office 365 is a benefit from buying Office licensing through your ESS agreement. This licensing is unlimited (started way back as a fixed number matching your Office ESS licensing, then they gave you the option to buy them through the shop at £0 and now they set it to unlimited for ease, smarter choice) and is there for Staff and Students to install on their personal devices (up to 5 per account, this includes mobile Office 365 apps). As mentioned above the Office 365 CTR method does cost more compared to EES on a grander scale however is handy for small primary schools that only need a handful of installs however they are technically account bound licenses and should only be installed on devices that a teacher uses (e.g. Their laptop) not for shared computers. I did hear news MS we're looking at a devices model for situations where a small handful of people used 2/3 machines in turn as this scenario wasn't covered by Office 365 CTR licensing model so this could be it, I will have a looksie later. Edited August 7, 2017 by Tefters
thegavna Posted November 30, 2017 Posted November 30, 2017 Encountered this problem yesterday thought I`d share just in case others experience the same. We recently setup a Hybrid office 365 deployment with Azure AD Connect seamless SSO a couple of months back for Firefly but it turns out I had missed the GPO setting "Allow Updates to status bar via script". https://docs.microsoft.com/en-gb/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start#browser-considerations Another issue I encountered is that if a Office 365 account has a personal and work onedrive account associated to that email address it will fail to sign in automatically.
chrisgirdler Posted December 11, 2017 Posted December 11, 2017 You don't need the Office 365 CTR for SSO to work with Office 365 logins, I currently have Office 365 Pro Plus on a Windows 10 1607 image with Office 365 SSO working absolutely fine through an ADFS server and then a WAP server for extra DMZ security. Last time I looked and tested this was Thursday last week. Just to clarify, are domain users automatically signed in with their O365 accounts and SSO, or are they required to enter their email address first?
Tefters Posted December 11, 2017 Posted December 11, 2017 Just to clarify, are domain users automatically signed in with their O365 accounts and SSO, or are they required to enter their email address first? Automatically signed into Office 365 on installed Office and email entry only on web front, although you can enter any email address and it will auto sign-in, eg. I just enter [email protected] and it knows who I am anyway from AD ticket and signs me in regardless, stupid I know but Microsoft for ya!
chrisjako Posted December 12, 2017 Posted December 12, 2017 Follow this article https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start
mullet_man Posted March 20, 2018 Posted March 20, 2018 Did you manage to sort this? Noticed it's happening here, mostly for students. Use to sign in automatically now Word/Excel etc just sat at Sign In in top right hand corner. Not sure why, the only thing that's changed is IAMCloud have altered there URLs. Any ideas where logs are kept for Office and signing in?
ifarmery Posted September 25, 2018 Posted September 25, 2018 Sorry to drag up and old post, I'm having this exact issue. Did you manage to solve this issue? Its driving me insane! Hi, We have a similar but slightly different problem with Office 2016 on W10. It does auto sign in but there are no connected services, or file history. The odd thing is if you sign out, then in again to office, it works and doesn't prompt for password. OWA in IE or edge does SSO. We only have a few office policies Microsoft Office 2016/Miscellaneous Block signing into Office Enabled Block signing into Office Org ID only Microsoft Office 2016/Privacy/Trust Centerhide Disable Opt-in Wizard on first run Enabled
HCC Posted October 3, 2018 Posted October 3, 2018 Hi, Sorry, don't know exactly what fixed it. Here are the things I remember changing: allowing the Office 365 category in smoothwall for all, and added a few allow urls I found in a Microsoft Office 365 firewall document that were missing from smoothwalls list. Switched from the normal 'Office 2016'; to Office 365 click to run with device based activation. Made changes to the internet settings as per https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start We had directory provisioning on for azure connect to filter only user OUs. I had to tick Windows 10 Computer OUs as well https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering changed Office 365 to modern auth. Hope that helps.
ifarmery Posted October 4, 2018 Posted October 4, 2018 Thank you It turned out that this registry key - https://support.microsoft.com/en-gb/help/4025962/can-t-sign-in-after-update-to-office-2016-build-16-0-7967-on-windows-1 solved all my woes
robbie-w Posted November 3, 2018 Posted November 3, 2018 We are having the same issues now but not throughout. User is showed as signed in on Office 365 Apps but connected services do not appear unless you sign out off the app and back in If anyone has any ideas would be appreciated. Have tried bypassing Smoothwall by putting in an exception to no avail. Tried uninstalling AV. We are using Azure SSO but the same problems were there with ADFS Robbie
HCC Posted November 5, 2018 Posted November 5, 2018 I remember having to add several urls to smoothwall's Office 365 category that were missing, but if it works for some its unlikely to be that. Are they all on the same Office and Windows versions?
abaxter2 Posted November 5, 2018 Posted November 5, 2018 We are using Azure AD connet and over the summer added hybrid join: https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains And since doing this users are signed into office clients / Microsoft store etc - if you are only using Azure AD connect it might be worth checking this feature out.
robbie-w Posted November 5, 2018 Posted November 5, 2018 I remember having to add several urls to smoothwall's Office 365 category that were missing, but if it works for some its unlikely to be that. Are they all on the same Office and Windows versions? I tried giving the user a complete bypass from Smoothwall and no luck. Also tried to remove all but the need GPO's for Azure SSO and that had no effect Office version seems to be 1809 and upwards, Windows is on 1803 but in early stages of quantifying the issue. Users show as signed into Office but connected services are not auto adding Robbie - - - Updated - - - We are using Azure AD connet and over the summer added hybrid join: https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains And since doing this users are signed into office clients / Microsoft store etc - if you are only using Azure AD connect it might be worth checking this feature out. Will take a look Thanks
robbie-w Posted November 5, 2018 Posted November 5, 2018 We are using Azure AD connet and over the summer added hybrid join: https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains And since doing this users are signed into office clients / Microsoft store etc - if you are only using Azure AD connect it might be worth checking this feature out. Can you confirm if Hybrid join free to use? If it is I'll get about setting it up. The only concern is the issue was happening even when we were on ADFS Robbie
abaxter2 Posted November 5, 2018 Posted November 5, 2018 Yes Hybrid join is free - part of Azure AD connect. Before I used Hybrid join I did have Azure AD connect setup with SSO, but found that even tho my users was signed into the Office clients they were not signed in to "connected services" such as OneDrive etc, after setting up Azure AD connect with SSO and hybrid join all works as it should (on my setup anyway) if you are already using Azure AD connect for SSO I would say give hybrid join a go to see if this helps. 1
robbie-w Posted November 5, 2018 Posted November 5, 2018 Yes Hybrid join is free - part of Azure AD connect. Before I used Hybrid join I did have Azure AD connect setup with SSO, but found that even tho my users was signed into the Office clients they were not signed in to "connected services" such as OneDrive etc, after setting up Azure AD connect with SSO and hybrid join all works as it should (on my setup anyway) if you are already using Azure AD connect for SSO I would say give hybrid join a go to see if this helps. Thanks for the tip on it now seems straightforward! Robbie
robbie-w Posted November 5, 2018 Posted November 5, 2018 Thanks for the tip on it now seems straightforward! Robbie Ok we are hybrid joined. I have freshly installed office and activated(it wouldn't let me activate the installed version hence the reinstall, probably another problem to solve) Still there are no Connected Services
abaxter2 Posted November 5, 2018 Posted November 5, 2018 I can see that device is activated with a: onmicrosoft.com account - do your users sign in with a onmicrosoft.com account? or a custom domain? if a custom domain is this setup in azure ad connect? You can also check that the hybrid join has worked by going to the azure portal > Azure active directory > devices and search for the device - you should then see the device listed under JOIN TYPE as "Hybrid Azure AD joined"
robbie-w Posted November 5, 2018 Posted November 5, 2018 After another user logged in the Device Activation "this belongs to" has disappeared from Office -> Account. Weird goings on!!!
robbie-w Posted November 5, 2018 Posted November 5, 2018 I can see that device is activated with a: onmicrosoft.com account - do your users sign in with a onmicrosoft.com account? or a custom domain? if a custom domain is this setup in azure ad connect? You can also check that the hybrid join has worked by going to the azure portal > Azure active directory > devices and search for the device - you should then see the device listed under JOIN TYPE as "Hybrid Azure AD joined" The internal domain that the users log into is empire.boston.ac.uk, their email and UPN is @student.boston.ac.uk but activating office using our tenant onmicrosoft.com domain. empire.boston.ac.uk is not setup in Azure ad connect but @student.boston.ac.uk. Hybrid join uses empire. PC's are showing up as Hybrid joined in Azure see attached image below
abaxter2 Posted November 5, 2018 Posted November 5, 2018 The internal domain that the users log into is empire.boston.ac.uk, their email and UPN is @student.boston.ac.uk but activating office using our tenant onmicrosoft.com domain. empire.boston.ac.uk is not setup in Azure ad connect but @student.boston.ac.uk. Hybrid join uses empire. PC's are showing up as Hybrid joined in Azure see attached image below [ATTACH=CONFIG]50795[/ATTACH] Is SSO working? IE: a user goes to outlook.office.com/owa and is signed in without entering a password etc? also in the office client such as Word is the user still signed in? and is just missing the connected services? Also in your last post you mentioned that the "Belongs to:" is missing - I can confirm this is the same with my clients and at this stage putting that bit down to an update. 1
robbie-w Posted November 5, 2018 Posted November 5, 2018 Is SSO working? IE: a user goes to outlook.office.com/owa and is signed in without entering a password etc? also in the office client such as Word is the user still signed in? and is just missing the connected services? Also in your last post you mentioned that the "Belongs to:" is missing - I can confirm this is the same with my clients and at this stage putting that bit down to an update. It is possibly down to an Office update but unable to figure out how to confirm Users autologin fine when going to outlook.office.com/owa and in the office client the user is still signed in and is just missing the connected services
abaxter2 Posted November 5, 2018 Posted November 5, 2018 (edited) It is possibly down to an Office update but unable to figure out how to confirm Users autologin fine when going to outlook.office.com/owa and in the office client the user is still signed in and is just missing the connected services I am sure you would have already done this as part of the SSO, but I did have to turn on modern authentication in Exchange Online: https://support.office.com/en-us/article/enable-or-disable-modern-authentication-in-exchange-online-58018196-f918-49cd-8238-56f57f38d662?ui=en-US&rs=en-US&ad=US Edited November 5, 2018 by abaxter2 1
robbie-w Posted November 5, 2018 Posted November 5, 2018 I am sure you would have already done this as part of the SSO, but I did have to turn on modern authentication in Exchange Online: https://support.office.com/en-us/article/enable-or-disable-modern-authentication-in-exchange-online-58018196-f918-49cd-8238-56f57f38d662?ui=en-US&rs=en-US&ad=US I missed this part but have now done it for Exchange and Skype. This has had no effect on "Connected Services". I might check it is enabled on SharePoint as well
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now