KK20 Posted November 26, 2019 Posted November 26, 2019 (edited) Im within touching distance of getting this working but something is amiss. ADFS with WAP set up. Office 365 A1 plan only. First of all, I can SSO to office 365 if I use a domain hint with https://office.portal.com?domain_hint=domain.co.uk If I use https://office.portal.com then I get asked to provide sign in details (domain email only, I never need to provide a password), the email is enough to get me past the SSO. External to our domain then obviously our ADFS page is presented where I need to provide the password. How can I avoid the request for sign in details so that I dont need to use a domain hint? I ask this as I plan to leverage office 365 logons for other SSOs? I want to avoid launching https://office.portal.com?domain_hint=domain.co.uk at startup if possible (seems a bit of a hacky solution). This behaviour is the same in Chrome, Edge and IE11 (I added WIASupportedUserAgents for other browsers) Edited November 26, 2019 by KK20
chaplic Posted November 28, 2019 Posted November 28, 2019 You can't. Hence the need for domain hint. O365 needs to know 'where to go go next'. Trivia, you can put any old rubbish before the '@' and it'll still sign you in Hybrid Azure AD Domain Join may make things a little quicker, but for the 'true SSO' you want, look at seamless single sign on and password hash sync (I'm not sure in this age why you would prefer ADFS?)
KK20 Posted November 29, 2019 Author Posted November 29, 2019 ADFS was simply the MS guide I used at the time (ADFS has been running for some time but not really used - I set up ADFS initially as a login for our adobe products, oh the irony). I'm happy to hybrid but do not want to move fully into azure AD only at this time - I want to remain "onsite" for some time yet. Thank you for the advice.
chaplic Posted November 29, 2019 Posted November 29, 2019 ADFS, PTA and PHS (with SSSO) -boy do we love TLAs- all do the same thing, glue your one premise identity into office365. ADFS is easily the most complex and places heavy reliance on your on-premise stuff, and has very few advantages, so if you're starting out I would not start there! Besides, PHS with SSSO is the only thing that approachs the username-less experience you want (but it's not flawless either)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now