Jump to content

Recommended Posts

Posted

Not sure which forum this fits into, so if this isn't correct please move...

 

I am absolutely tearing my hair out with this one! Looking in to why our Azure AD Seamless Single Sign-On working properly had led me to believe that for some reason this was happening:

"If you have enabled both Azure AD Join and Seamless SSO on your tenant, ensure that the issue is not with Azure AD Join. SSO from Azure AD Join takes precedence over Seamless SSO if the device is both registered with Azure AD and domain-joined. With SSO from Azure AD Join the user sees a sign-in tile that says "Connected to Windows".

We did start using Hybrid Azure AD Join as we were going to to it for our mobile devices, we decided to not pursue it so I disabled this GPO to stop it happening:

"Computer Configuration > Policies > Administrative Templates > Windows Components > Device Registration"

To my memory we haven't set up Hybrid Azure AD join in Azure AD Connect and when I look at the settings, it tries to step me through the process to set it up.

However, we're still getting that "Connected to Windows" pop up AND we have a ton of domain devices registered in Azure AD and I cannot fathom why!

Please help!

Posted

My understanding of this is:

 

What you are seeing is when your are not using / setup "Hybrid Azure AD join", SSO will work for browsers but if a users opens an Office client such as Word / app and signs into get his or hers Onedrive / SharePoint it will then prompt to add his or hers account to either this app only or windows - the default is windows, hence why you will see these entries in Azure AAD - This is what I used to see until I setup Hybrid Azure AD join, while I was setting up Hybrid Azure AD join (out of hours) I removed all the entries that included any local domain pc with the listing of "Connected to Windows" Once the Hybrid join was complete all I see is one listing for each local domain device listed as "Hybrid Azure AD joined"

Posted
So, are you saying that setting up Hybrid Azure AD is the way to resolve this and am I being a bit fussy about seeing our local domain devices in azure ad? The main issue we're trying to resolve is the seamless single sign-on isn't working properly. It works fine in the browsers but is a bit poop when it comes to Office and mapping SharePoint/OneDrive, which we are using IAM Cloud for.
Posted (edited)

I found that before I had setup Hybrid Azure AD join, SSO worked fine for browsers but did not show the users OneDrive / SharePoint in Office clients such as "Word" under "Connected Services" but after rolling out Hybrid Azure AD join this was no longer the case and SSO was working for browsers and apps, and did show the users OneDrive and SharePoint under "Connected services" and user could access this data, it also stopped prompting the user to add his or hers account to either this app only or windows. I now only see one entry for each local domain device listed as "Hybrid Azure AD joined"

 

The other + with Hybrid join is the users are also single signed into the Microsoft store - so if you have setup the Microsoft Store for Business / Education you can force via GPO to only show the private store.

 

When setting up "Hybrid Azure AD join" you have the option of only syncing selected OU's, so as a test to see if this meets what you require you could just select a few devices in a test OU, and if it does meet what you require you just go back and select the other OU's. For me I wanted control over what OU's got synced and did not want to hybrid azure AD join my servers for example.

 

In my case "Hybrid Azure AD joined" has worked great and meet all my requirements, but of course this solution might not be what you are after.

 

(EDIT - I should also mention that sso with connected services within office clients will only work on office clients that use modern authentication - some older version will work with a reg hack, and of course I was already using Azure AD connect - sync, to sync my users)

Edited by abaxter2
  • Thanks 1
Posted

Cool. Yeah we're all up to date with Windows 10, up to date with Office as well. Have to say, I'm pretty pleased with the solution we're running at the moment, just the SSO bit is the last bit that is being particularly difficult and it's the bit all users grumble about. My only worry being that if it's not right for us, we've still got our users somehow registering local domain devices in AAD.

 

Cheers for the tips though, will report back when we've had a good look at it.

Posted
I found the GPO setting mentioned doesn't stop PCs hybrid joining. You've then got to clear out all the Azure AD registered domain PCs from intune via powershell. MS say the scenario isn't supported. There is a new GPO setting for 1809 that stops Workplace Join/AzureAD registered or you can block the AAD modern app via applocker.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...