Jump to content

Recommended Posts

Posted

Been reading around this for a while and wondering if anyone is using it...

 

So it seems with Office 365 \ Azure AD services you have a couple of options

 

  • basic user password sync, no SSO
  • ADFS (or equivalent 3rd party) Federated SSO
  • Azure AD Connect Passthrough SSO

In most cases it seems ADFS or Passthrough Auth give similar user experiences e.g. Office SSO, browser O365 apps SSO etc.

 

What I'm looking at is whether to go further and do the Hybrid AD Join where internal Windows 10 machines are joined to both the local AD and Azure AD. That seems to rely on Azure AD Connect and running the dnscmd command on scheduled task.

 

The main advantage I can see is...

 

  • Windows Store for Education SSO (currently relies on entering a username \ password even with ADFS in place)
  • struggling to find anything else...

@Arthur have you tried this at all?

Posted

The Azure self service password reset can be accessed via the login screen on Windows 10 1803+.

Co-Management with SCCM. You can apply intune policies.

Posted
We went down the route of: Azure AD connect pass through last year - works great for browser SSO but did find that local AD devices did not sign the users into office clients (word etc) did the hybrid join this summer with my annual windows 10 upgrade and now SSO works for all Microsoft services, so far very happy with the outcome.
Posted (edited)
We went down the route of: Azure AD connect pass through last year - works great for browser SSO but did find that local AD devices did not sign the users into office clients (word etc) did the hybrid join this summer with my annual windows 10 upgrade and now SSO works for all Microsoft services, so far very happy with the outcome.
Do you find signing into the OneDrive sync client are more reliable? Edited by free780
Posted (edited)
The Azure self service password reset can be accessed via the login screen on Windows 10 1803+.

Co-Management with SCCM. You can apply intune policies.

 

@free780 you paid the MS tax for AAD Premium then? Came out silly expensive for us with the per-user pricing :(

 

@abaxter2 what exactly did the Hybrid Join entail on clients, was it pretty much automatic?

 

At the moment we're using a Centrify SaaS cloud-based ADFS-esque solution, which does SSO for everything apart from the Windows Store (which seems generally pretty shoddily implemented but we'd need to migrate to SCCM to be able to deploy the Modern Apps directly to clients). For the OneDrive client you need to make a couple of registry edits as per https://gshaw0.wordpress.com/2017/11/08/onedrive-files-on-demand-first-steps/

Edited by gshaw
Posted (edited)
@free780 you paid the MS tax for AAD Premium then? Came out silly expensive for us with the per-user pricing :(

 

@abaxter2 what exactly did the Hybrid Join entail on clients, was it pretty much automatic?

 

At the moment we're using a Centrify SaaS cloud-based ADFS-esque solution, which does SSO for everything apart from the Windows Store (which seems generally pretty shoddily implemented but we'd need to migrate to SCCM to be able to deploy the Modern Apps directly to clients). For the OneDrive client you need to make a couple of registry edits as per https://gshaw0.wordpress.com/2017/11/08/onedrive-files-on-demand-first-steps/[/quote @gshaw Well EMS does cost but a lot of software will be going down the per user licensing model. In education it's usually based on staff FTE. I think Microsoft 365 will be going down this route anyway to slowly push edu to.the cloud.

Edited by ChrisH
Posted
@free780 you paid the MS tax for AAD Premium then? Came out silly expensive for us with the per-user pricing :(

 

@abaxter2 what exactly did the Hybrid Join entail on clients, was it pretty much automatic?

 

At the moment we're using a Centrify SaaS cloud-based ADFS-esque solution, which does SSO for everything apart from the Windows Store (which seems generally pretty shoddily implemented but we'd need to migrate to SCCM to be able to deploy the Modern Apps directly to clients). For the OneDrive client you need to make a couple of registry edits as per https://gshaw0.wordpress.com/2017/11/08/onedrive-files-on-demand-first-steps/[/quote @gshaw Well EMS does cost but a lot of software will be going down the per user licensing model. In education it's usually based on staff FTE. I think Microsoft 365 will be going down this route anyway to slowly push edu to.the cloud.

Don't know what I did there. The spending decision wasn't mine just looking at getting good value by using all the features.
Posted (edited)

What I'm looking at is whether to go further and do the Hybrid AD Join where internal Windows 10 machines are joined to both the local AD and Azure AD. That seems to rely on Azure AD Connect and running the dnscmd command on scheduled task.

 

The main advantage I can see is...

 

  • Windows Store for Education SSO (currently relies on entering a username \ password even with ADFS in place)
  • struggling to find anything else...

@Arthur have you tried this at all?

 

We've recently done this. We use ADFS 4.0 and from AD Connect v 1.1.819.0 onwards, it's crazy simple to enable Hybrid Azure AD Join for devices. AD Connect will allow you to do all this from within the AD Connect connection wizard and it will take care of service point config and ADFS configuration if needed.

 

In terms of value of doing it, you can then use the results to apply intune policies to devices and users, to make SSPR from the Windows 10 login screen, store for education, deliver always-on VPN. There's quite a few things that Microsoft really would prefer us all to be doing with "Modern Management" these days and are therefore easier to do from intune.

 

Super-easy to set up, works really well.

Edited by Roberto
  • Thanks 2
Posted
We've recently done this. We use ADFS 4.0 and from AD Connect v 1.1.819.0 onwards, it's crazy simple to enable Hybrid Azure AD Join for devices. AD Connect will allow you to do all this from within the AD Connect connection wizard and it will take care of service point config and ADFS configuration if needed.

 

In terms of value of doing it, you can then use the results to apply intune policies to devices and users, to make SSPR from the Windows 10 login screen, store for education, deliver always-on VPN. There's quite a few things that Microsoft really would prefer us all to be doing with "Modern Management" these days and are therefore easier to do from intune.

 

Super-easy to set up, works really well.

 

There's plenty I would've been using for 2-3 years now but when your EES costs £20k and AAD Premium \ EMS was £10k on its own due to the per-user instead of FTE model it becomes very hard to justify. We've had to use a different password self-service instead and InTune has been on my wish list for a long time now. One day, one day...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...