Jump to content

Recommended Posts

Posted

Hi, I have set up Azure AD Connect and and enabled SSO so my users can browse to outlook.office365.com/owa/mydomainname.sch.uk and they are automatically signed in to Office 365 email and apps, as far as ic an tell that's all working fine.

 

Staff are starting to use onedrive as we have upto 1tb of free storage per user as we've now banned pendrives. It would be ideal to allow them to use the onedrive feature built into Office 2013 for saving and opening files, however i cant seem to figure out how to get it to automatically sign in via the application, instead they are asked to enter their credentials.

 

In the top right hand corner it shows their email address and has the option to sign out but that must be the local domain account as connected services are not joining.

 

Has anyone managed to get this to work? a quick google suggests it should work automatically but i'm not sure.

 

Cheers

 

Liam

Posted

Will have a read of that and let you know how i get on, probably going to upgrade to 2016 over summer so probably have to start again.

 

I've just set a GPO to "block sign-in" and allowed only organisational accounts but that seems to have removed onedrive all together.

 

I'll have a play with that link in the morning thank you.

Posted
Sorry, I can't help with your question but regarding the SSO config, can I just ask; Within AD Connect, are you only syncing user accounts or also Devices (computer accounts)?
Posted (edited)

Not yet had chance to fiddle with Office 2013 to update everyone, but seems to work okay in Office 2016 so i'm probably just going to push that out as soon as possible and test that.

 

BirtyBassett, i'm only syncing users up to Azure AD, i'm not sure if you can sync Computer Accounts, i believe you can use Azure AD as a cloud 'Active Directory' as we know it, called Azure AD DS, but thats a premium feature i don't really need nor want so i've not really looked into that.

 

EDIT: Apologies, upon a bit of investigation I've also read that computers need to be synced via Azure AD Connect in order to become "Domain Joined" in the devices section, i didnt realise as i had synced my entire AD forest anyway to allow for future OU's to be created and not have to re-configure sync options. Not sure if its true or not but i'd recommend syncing the computers OU too jsut incase, its all part of the same step in setup anyway so it doesn't take any extra configuration

Edited by liamrobinson
Posted

Thanks Liam, that's good to know. I have read that you need to sync comp accounts in order to get SSO working. I guess not!

 

Regarding your Office SSO, are you using C2R or MSI?

Posted (edited)
Thanks Liam, that's good to know. I have read that you need to sync comp accounts in order to get SSO working. I guess not!

 

Regarding your Office SSO, are you using C2R or MSI?

 

You do need to tweak a few things and add connectors to your domain for it to work properly, main one being adding certain URLs to local intranet settings, its easy enough via a GPO, i'm going to create a blog post about how i set mine up for my future reference and to help others if they are struggling, will post it up soon once i've written it.

 

We're using MSI for Office 2013 which is deployed via System Centre 2012, i didn't originally set that that up so i'll have to do a bit of digging how to push out Office 2016 via SCCM.

 

I've already set up my KMS host for Office 2016 today and tested it against a few manual installs i have on the network and it seems to be working, so i'm hoping for a smooth roll-out and activate, but as we know doesn't always work like that!

 

There is then the option of installing Office 365 Proplus to the network, which activates via the users email address/azure account but i'm not sure if that's gonna cause any issues in a domain environment, say we lose internet connection for the day etc, plus i've never really looked into Office 365 Proplus, apart from installing it via my work email on my Spare PC (each user gets 5 installs) - If anyone has any ideas regarding this would be great!

 

EDIT: Apologies, upon a bit of investigation I've also read that computers need to be synced via Azure AD Connect in order to become "Domain Joined" in the devices section, i didnt realise as i had synced my entire AD forest anyway to allow for future OU's to be created and not have to re-configure sync options. Not sure if its true or not but i'd recommend syncing the computers OU too jsut incase, its all part of the same step in setup anyway so it doesn't take any extra configuration

Edited by liamrobinson
Posted

Update SCCM to Current https://docs.microsoft.com/en-us/sccm/core/plan-design/changes/what-has-changed-from-configuration-manager-2012.

 

Use that to deploy Office 365 Monthly Channel to new workstation builds https://docs.microsoft.com/en-us/sccm/sum/deploy-use/manage-office-365-proplus-updates. Since Office 365 16.0.8730 (December 2017) it is so far ahead of 2013 in terms of cloud integration and reducing friction around sign-on etc.

 

Our Win10 machines are not AzureAD joined due to a config weirdness - but Office client sign-on and activation is now automatic and transparent on the Monthly branch https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso

  • Thanks 1
Posted

Thanks Psydii, so you'd recommend pushing out Office 365 instead of Office 2016?

 

I've only just started to dabble with Win10, only Me and the IT apprentice have Windows 10 so not yet really looked at "Domain Joined" Devices in Azure AD, my surface tab is however hybrid domain joined whatever that means!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...