Jump to content

Recommended Posts

Posted

Hi,

 

To most of you this may come across as a really noob question but im fairly new to the world of cloud computing and Office 365 so appologise in advance but would really appreciate any input from people who have already implemented Azure AD Connect in their environments.

 

Currently we use Windows 7 with a view to moving to Windows 10 next year and we use Office 365 but only really for the Mail side of things and we are really trying to push some of the other services. I am currently in the testing phase of implementing Azure AD Connect Single Sign on. In my testing area I am able to set the user sign-in options to Password Synchronization and it pulls my tests users AD credentials across to their Office 365 account so that they can log in with the same password as their AD account but this isnt really want we want. What we really want is a true single sign on experience where the user signs in to the computer with their AD credentials and when they go to the Office 365 landing page it logs them in automatically and i have been looking at pass-through authentication in Azure AD Connect.

 

The problem im having is when I am trying to setup Azure AD Connect to use pass-through authentication it doesnt work. I run the AD Connect setup and select pass-through authentication with single sign on. I run through the setup until i get to Azure AD sign-in configuration which lists my AD UPN Suffix. The suffix that we use for our email addresses is listed as verified and the suffix for our local domain is listed but says not added with a message at the bottom stating that Users will not be able to sign-in Azure AD using their on premise credentials. Do I need to do anything addtional here to make this work? Ive been reading about changing DNS settings in the Azure Portal but when i look into that it seems we have to pay for the premium version of Azure. Do i actually need to change any DNS settiings in the cloud or on site and for me to get the single sign on experience i want do i really need to pay for the premium version of Azure?

Posted

You'll make your life a lot easier if your internal domain UPN matches the domain in Office365.

 

You shouldn't cause any trouble by changing internal users' UPN, in my experience. Simply add your Office365 domain as a UPN in AD and change each user's UPN in Active Directory Users and Computers.

Posted
Using administrator account delete C:\Users\username and in regedit go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ select each folder and see if the ProfileImagePath key is the location of the profile you just deleted. Delete the folder so it can recreate when you next log in.
Posted
I think I have sorted it. I had set up AD Connect a few days ago before I had changed the UPN in the test users account. AD Connect during the setup runs a full sync but obviously must not have picked up the UPN correctly or something. I deleted the test user out of AD, recreated with the Office 365 UPN set and then ran a full sync then logged back into the exact same computer where it was previously loading a temp profile with the exact same username to test whether it was profile corruption and it was fine. This is going live to about 1400 users tomorrow so fingers, toes and lots of other things crossed.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...