pow Posted September 12, 2017 Posted September 12, 2017 So, bear with me here! I am trailing Chromebooks. I have set up our google apps tenant to link to our Azure AD which is populated by our onsite directory. I have enrolled the device into the portal, works lovely, just have to add a user to an AD group and wait an hour. I can sign into the chromebooks using onsite credentials (which are synced to Azure AD for our Office365 tenant, we use all the 365 services, then signed in via SSO for google apps) but, you have to enter your username 3 times which isn't ideal, once into the google screen, once into the Office365 screen, once into the ADFS front end. Once signed in, I get SSO into all the 365 apps which is awesome though! When the chromebook is opened, I get a message saying: This device is managed by gafe.schooname.com (I set up google apps on a subdomain and added our main domain... may have been a bad idea?). Please click next to continue signing into your gafe.schoolname.com account. When I click next I get Please Wait spinny wheel back to the same message. If I click Sign in with a different account, I can sign in using my onsite/O365 username, but I get it in this order: Google sign in page (I put in my username), O365 sign in page (I put in my username again), ADFS sign in page (finally can put in username and password). Is there any way to streamline this process?
pow Posted September 12, 2017 Author Posted September 12, 2017 Small update, worked out it was the proxy blocking the next button redirect, so now the next button brings me to the Office365 signin page which then redirects to our sts page - just want to land straight at that really!
pow Posted November 14, 2017 Author Posted November 14, 2017 No, I just accepted you have to do a double username. I _think_ the new office365 signin page will sort this though - it asks for the username and then redirects to our sts page with the username already filled in which is nice!
FN-GM Posted November 14, 2017 Posted November 14, 2017 This post is assuming you're using ADFS. To get rid of the double username prompt on the login screen enable this policy under device settings: name: Single Sign-On IdP Redirection Setting: Allow users to go directly to the SAML SSO ldp page As for the sign in to Office 365. You could create a custom app that uses the SSO url. EG OWA will point to https://outlook.com/school.lea.sch.uk https://support.google.com/chrome/a/answer/2714278?hl=en
pow Posted November 14, 2017 Author Posted November 14, 2017 Ahh yes, thank you FN-GM, I'll take a look at that later, thanks for the guidance!
FN-GM Posted November 14, 2017 Posted November 14, 2017 Using those methods I have had Chromebooks working with SSO on Office 365.
pow Posted November 14, 2017 Author Posted November 14, 2017 name: Single Sign-On IdP Redirection Setting: Allow users to go directly to the SAML SSO ldp page That's already set to this - but it takes you to the login.microsoftonline.com page, where you need to enter your email address twice to get to our sts page. Under Security Settings - Setup SSO with 3rd party identity provider the signin page URL is set to: https://login.microsoftonline.com/guid/saml2, no matter what I set that to (I was trying variations of our sts page url) it just won't allow it.
pow Posted November 14, 2017 Author Posted November 14, 2017 What URL are you using under that sign-in page url? Yes - ADFS setup.
FN-GM Posted November 14, 2017 Posted November 14, 2017 Is ADFS setup on both G Suite and Office 365? What Sign-in page URL?
pow Posted November 14, 2017 Author Posted November 14, 2017 https://login.microsoftonline.com/99xxxxx4-58xx-4918-b1xx-79xxxx30a34/saml2 Removed some charaters as they are unique to us
FN-GM Posted November 14, 2017 Posted November 14, 2017 I have no idea where you would put this URL? Is ADFS setup on both G Suite and Office 365?
pow Posted November 14, 2017 Author Posted November 14, 2017 No, just Office365, then Azure SSO to G Suite
FN-GM Posted November 14, 2017 Posted November 14, 2017 You will need to setup ADFS on both G Suite and Office 365 then break that Azure SSO link. I did it with G Suite recently on ADFS 2016 with this guide. A few things are different but 99% is the same - Google Apps and Active Directory Federation Services –
rrosing Posted October 7, 2020 Posted October 7, 2020 Sorry for the reply to this old topic but how did you fix this? I have the same issue. I have federated adfs with azure ad. 2 login screens now on Chromebooks. And FN-GM what do you mean by setting up ADFS on Azure and G suite. In Gsuite i setup Azure as the IDP instead of ADFS. When i setup ADFS as IDP password changes are not updated to already logged in accounts on Chromebook. Then a user still needs to use the old password to login.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now