Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

[O365] Adding domain alias / username alias to make logon easier


Recommended Posts

Posted

Hi,

We use Office 365 with Azure AD. Students logon using their email address. We long usernames and passwords, making logon time consuming for young students.

 

How easy is it to:

1) Add a domain alias, so everything else (email addresses etc...) remains the same, but users can log on using a shorter address if desired. Ideally both long and short would work simultaneously and both emails would work.

 

2) Add an alternative user ID for users. So they could log in with [email protected], or alternatively could logon using [email protected]

 

Many thanks,

Posted

If this is just regarding login time wouldn't it be easier to setup an SSO? Then there's no need to change emails/add more etc. They just get logged in when they browse to emails.

 

If you wanted to add an additional one you could, but then you're going to have issues with things like what domain is replied to, what user has what username. If they reply from the shortone do people know who it is etc

 

Steve

Posted
If this is just regarding login time wouldn't it be easier to setup an SSO?

Thanks Steve. Will SSO work on Macs? If the macs were domain joined would the SSO work in Chrome/Safari and Office Desktop itself?

Even if we did have SSO, surely they still need to enter their email? I thought the SSO only kicked in after users are directed to their site ADFS page?

 

If you wanted to add an additional one you could, but then you're going to have issues with things like what domain is replied to, what user has what username. If they reply from the shortone do people know who it is etc

 

I was hoping that the primary address would remain as default and the secondary address could be just used for logging in?

Posted

The support configs are these for AADC SSO - https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso

 

ADFS might work differently as we don't use it, but pretty sure it should work the same. Just means you point their email shortcut to your "smart-link" and it'll pull across the required details as long as it's setup on the server side etc. No email or password entry required.

 

In our case, we have the email link on our VLE (Smart link prepared for SSO), this when clicked checks their auth details against the AADC SSO and if matched to a user logs them in with no entry of anything. Only if it fails (and that's normally internet issues or a user without an email) it'd fall back to normal login method.

 

If you want it for use on software e.g. local apps it works via Modern Authentication too: https://blogs.office.com/en-us/2015/11/19/updated-office-365-modern-authentication-public-preview/

 

In regards to your other option, Yes you could set up a secondary URLdomain and link it to your office. Then locally in AD etc or whatever is syncing your users add a secondary proxy address, and change them to login via that.

 

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...