Jump to content

Recommended Posts

Posted

Hi everyone

 

so I have SSO working with office 365 and for the most part its very good although even though this is working I am still asked to either click my email address to login or click email address and then select work created account before it will allow me to login.

 

This is the same with SharePoint online I need to do the above.

 

Has anyone managed to get a way around this so that from domain computers the domain user does not need to click anything but it seamlessly login to SharePoint/office? I understand outside of the office the need for the login which is fine but from within the domain while azure ad connect and single sign-on is working anyone managed to work around this?

 

I have tried adding the site to local intranet and also trusted sites testing both times but once I navigate to the site it still asks me to click on the email address and then click on work/school account (in which case SSO kicks in) and the user is logged in. The only issue with this is if I move to SharePoint 365 and direct this as the first loading page every morning all users will need to click their email and then click work/school account to access the SharePoint site (I know its not a massive issue) but trying to make it as seamless as possible.

Posted (edited)
You may need to add your Sharepoint site to Trusted Sites within IE, as well as 365 itself, Outlook and more. Edited by Michael
Posted

Thank you Michael I have tried that but it keeps prompting the user to click their email address before logging into the site which I am trying to bypass completely.

 

- - - Updated - - -

 

Thank you Jonah I will take a look at that now.

Posted

Which browser are you using? Have you added the browsers you want SSO to work for on the ADFS server?

I have added chrome which it works for, but I'm yet to add Edge so it prompts when using that browser. So could be related to that? That's if you are using ADFS!

Posted
I was in the process of setting up an ADFS server until I seen Microsoft released a new version of the Azure AD Connect which allows single sign on and so I am only using that not my own ADFS server.
Posted

We have the new AD Connect, but yet to move to it for SSO. We also use ADFS for Google Suite SSO (Yes, we have both!)

From reading up on AD Connect in the past, I believe other admins also had the same issue as you are having, which was down to cookies, could be related.

Posted
Thank you TSEARS I will clear the cookies and try again I was on with Microsoft for a while but although the SSO is working correctly its just trying to fine tune to suit ourselves or at least make it as simple as possible without the need to keep clicking email from domain computers - as I say from laptops outside the office I have no problem with this as an extra layer of security but from domain computers I was hoping that with SSO I could configure something which would allow automatic login to the services
  • 2 weeks later...
Posted
Thank you TSEARS I did try the cookies as a possibility but no it doesn't allow the SSO, at the moment it look like I am going to have to direct the page to the sharepoint link and have people click the email address before it will load. I am hoping that at some point this will change for domain machines because although the SSO works its still requires the end user to click the email account before the page will automatically load for them.
  • 2 months later...
Posted

HI Aaron,

 

I hope you are using Azure AD connect. If not install that. I will give you some links below, the most important one is where you have to add a couple of MS sites to your intranet zone via GPO. This will log your users ( to whom the GPO is applied), straight in. This is a working solution.

 

https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start -- gives the URLs of the MS web sites to be added via GPO

 

Test SSO connectivity. https://testconnectivity.microsoft.com/ -- This requires ADFS as it looks for ADFS to perform it's SSO tests. --- Very useful to test your connectivity levels and get an idea what's going on.

 

Hope this helps.

 

You need to set up a service account on AD that has Global admin permissions, login as that person to the server / computer where you install Azure AD connect. Then in stall AAD connect make sure your firewalls let the traffic through for that server etc.

 

You should be a happy person at the end of today. For me it took less that two hours after I found the above web sites and a re-install of AAD connect.

 

Best Wishes.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...