Jump to content

Recommended Posts

Posted

I am looking at starting to setup the ability to login to Chromebooks with Office 365 credentials.

 

Previously I believed that by enabling this meant that all users in GSuite would be required to authenticate to AAD, so any existing GSuite would no longer work.

 

However Google were introducing this on a Per OU level.

 

Does anyone know if this is possible yet? I do not want existing GSuite users to be affected by me enabling this.

Posted
If you've provisioned users from AD > Azure > G Suite or just Azure > G Suite, it'll work signing into a Chromebook. Linking Azure to G Suite will provision real Google accounts so you can login to any Google service.
Posted
If you've provisioned users from AD > Azure > G Suite or just Azure > G Suite, it'll work signing into a Chromebook. Linking Azure to G Suite will provision real Google accounts so you can login to any Google service.

 

So doing it this why does Azure send the password to the provisioned Google account as well?

Posted
Azure remains the ID Provider and they're bound by a certificate. I can only presume it's a hashed token that's sent to G Suite?

 

So that’s the problem I believe. Google does not support multiple identity providers and therefore if you enable this then it is for all Google users, not just a selection.

Posted

You can either do select users or the whole Azure tenancy. Then whatever the selection into G Suite.

 

What happens if you have existing users in G Suite, or manually create users in G Suite - I'm not 100% sure, but I see no issue so long as they don't match. If they did match, I'm not sure what happens in this scenario.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...