Jump to content

Chromebooks, Managed Device and Office365 SSO


Recommended Posts

Posted

So, bear with me here!

 

I am trailing Chromebooks. I have set up our google apps tenant to link to our Azure AD which is populated by our onsite directory. I have enrolled the device into the portal, works lovely, just have to add a user to an AD group and wait an hour. I can sign into the chromebooks using onsite credentials (which are synced to Azure AD for our Office365 tenant, we use all the 365 services, then signed in via SSO for google apps) but, you have to enter your username 3 times which isn't ideal, once into the google screen, once into the Office365 screen, once into the ADFS front end. Once signed in, I get SSO into all the 365 apps which is awesome though!

 

When the chromebook is opened, I get a message saying:

 

This device is managed by gafe.schooname.com (I set up google apps on a subdomain and added our main domain... may have been a bad idea?). Please click next to continue signing into your gafe.schoolname.com account. When I click next I get Please Wait spinny wheel back to the same message.

 

If I click Sign in with a different account, I can sign in using my onsite/O365 username, but I get it in this order:

 

Google sign in page (I put in my username), O365 sign in page (I put in my username again), ADFS sign in page (finally can put in username and password).

 

Is there any way to streamline this process?

Posted
Small update, worked out it was the proxy blocking the next button redirect, so now the next button brings me to the Office365 signin page which then redirects to our sts page - just want to land straight at that really!
  • 1 month later...
Posted
No, I just accepted you have to do a double username. I _think_ the new office365 signin page will sort this though - it asks for the username and then redirects to our sts page with the username already filled in which is nice!
Posted

This post is assuming you're using ADFS.

 

To get rid of the double username prompt on the login screen enable this policy under device settings:

 

name: Single Sign-On IdP Redirection

Setting: Allow users to go directly to the SAML SSO ldp page

 

 

As for the sign in to Office 365. You could create a custom app that uses the SSO url. EG OWA will point to https://outlook.com/school.lea.sch.uk

 

https://support.google.com/chrome/a/answer/2714278?hl=en

Posted

name: Single Sign-On IdP Redirection

Setting: Allow users to go directly to the SAML SSO ldp page

 

That's already set to this - but it takes you to the login.microsoftonline.com page, where you need to enter your email address twice to get to our sts page. Under Security Settings - Setup SSO with 3rd party identity provider the signin page URL is set to: https://login.microsoftonline.com/guid/saml2, no matter what I set that to (I was trying variations of our sts page url) it just won't allow it.

  • 2 years later...
Posted

Sorry for the reply to this old topic but how did you fix this? I have the same issue. I have federated adfs with azure ad. 2 login screens now on Chromebooks.

 

And FN-GM what do you mean by setting up ADFS on Azure and G suite. In Gsuite i setup Azure as the IDP instead of ADFS. When i setup ADFS as IDP password changes are not updated to already logged in accounts on Chromebook. Then a user still needs to use the old password to login.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...