Scorpio Posted February 9, 2019 Posted February 9, 2019 Hi everyone Looking to have all schools login passwords, email, etc synced between AD and Microsoft and Google, ive used AD sync where just Office 365 is used on the site and im fine with that. Do I still do this stage then get Google to sync from Azure ? Whats the process and is there any gotchas ? Dont want to mess up whats already in use, is there anything I shouldn't do or watch out for, known issues etc. The reason we need this is, the school uses all google services but they have large screen Chrome books, which requires a Microsoft login to use the OVS licensed version of Office on all the Chrome Books, think anything over 10" has to have a login, so as you can see we dont want 3 different logins / passwords which will cause hell, want them all to be sync and Seamless so its a single sign on / federated. Any pointers / articles would be great, thanks. S
robk Posted February 9, 2019 Posted February 9, 2019 You can point g-suite to authenticate from office 365. I think that will then do what you want.
ADMaster Posted February 9, 2019 Posted February 9, 2019 You can also use GCDS to sync accounts to google and GSPS to sync the passwords. I had my Gsuite environment before Azure so I'm running both sync tools. Its not SSO by definition, but its is the same username and password. I'd like to attempt SSO as suggested above, but that would break my clever badges.
Michael Posted February 9, 2019 Posted February 9, 2019 Hi everyone Do I still do this stage then get Google to sync from Azure ? Whats the process and is there any gotchas ? Dont want to mess up whats already in use, is there anything I shouldn't do or watch out for, known issues etc. I've done exactly this - AD > Azure AD Connect > Azure > G Suite Setting up the Google app in Azure was a little tricky, but it works great auto provisioning users and does provide an SSO experience.
snagrat Posted February 9, 2019 Posted February 9, 2019 I've done exactly this - AD > Azure AD Connect > Azure > G Suite Setting up the Google app in Azure was a little tricky, but it works great auto provisioning users and does provide an SSO experience. So users can login to Chromebooks with Azure credentials and then get into Gsuite and Office 365 with no additional credentials?
Scorpio Posted February 10, 2019 Author Posted February 10, 2019 I've done exactly this - AD > Azure AD Connect > Azure > G Suite Setting up the Google app in Azure was a little tricky, but it works great auto provisioning users and does provide an SSO experience. So you dont use the GCDS? As that would sync from AD on the Domain Controller, you use AD sync to sync AD into Azure, then you Connect G suite to Azure somehow ? What about if all accounts exists already, such as there is email accounts in google, logon accounts in AD and passwords are different or out of sync usually, how do you do this without causing a mess, has anyone done this ? Thanks S
Michael Posted February 11, 2019 Posted February 11, 2019 So users can login to Chromebooks with Azure credentials and then get into Gsuite and Office 365 with no additional credentials? Correct - the same credentials for each, but it is a real G Suite account, just provisioned from Azure automatically.
Michael Posted February 11, 2019 Posted February 11, 2019 So you dont use the GCDS? As that would sync from AD on the Domain Controller, you use AD sync to sync AD into Azure, then you Connect G suite to Azure somehow ? What about if all accounts exists already, such as there is email accounts in google, logon accounts in AD and passwords are different or out of sync usually, how do you do this without causing a mess, has anyone done this ? Thanks S Correct I don't use GCDS - as above, Azure AD Connect provisions users in Azure. Within Azure you can install the G Suite App, then within G Suite itself set it to look to Azure to provision users, which is secure using a free Microsoft generated certificate. If users exist in AD and O365 as a cloud account, it will be converted to a Synchronised account and will adopt the user's AD password. As to what happens if an account already exists in G Suite, I'm not sure, never tried it. There's nothing in G Suite to indicate the account is synchronised from Azure (to the best of my knowledge). 1
Scorpio Posted March 26, 2019 Author Posted March 26, 2019 Correct I don't use GCDS - as above, Azure AD Connect provisions users in Azure. Within Azure you can install the G Suite App, then within G Suite itself set it to look to Azure to provision users, which is secure using a free Microsoft generated certificate. If users exist in AD and O365 as a cloud account, it will be converted to a Synchronised account and will adopt the user's AD password. As to what happens if an account already exists in G Suite, I'm not sure, never tried it. There's nothing in G Suite to indicate the account is synchronised from Azure (to the best of my knowledge). Going to give this a go soon, might do some tests with dummy accounts in G suite to see what happens when account exists. If anyone has done this recently it would be good to hear from you. We are then looking to use the QR badges to log into windows and Chromebooks
Scorpio Posted April 13, 2019 Author Posted April 13, 2019 Hi Guys Started this. I've got local AD synced to Office 365, ive added the G suite Azure addon and added SSO on there, also added SSO in G suite, so this is initially just setting up SSO, which seems to work however i have a few queries: 1. When logging onto Gmail it asked to login Twice? 2. On Chromebooks i had to enable the SAML SSO for Chrome Devices in G suite, this then redirected to the Login.microsoftonline.com pages but it seems to ask twice for the email address? Is there a way of passing the email to the next screen automatically ? So i just need to enter once then when the screen pops up from Microsoft, just enter the password ? 3. It looks like the user can change the password in Google, how does this work as it seems to change the password in google but not to AD, so the passwords are different in AD and Google, its not a problem on devices that redirect to MS to login, but what about Phones that may use email apps, that will use the changed password in Google ? Do i need to use GSPS or do i have to do something else.? 4. What path do you guys use in the password reset in the Azure G suite plugin ? Its blank atm but should this be filled out ? Next after this I will do the auto provisioning, so many need some more help Many Thanks S
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now