Chuckster Posted September 15, 2021 Posted September 15, 2021 I have Azure AD Connect running and syncing my on-prem AD successfully. User accounts appear in Azure AD Portal as do workstations and other devices (confirmed via the command 'dsregcmd /status') How do I get Chrome, Edge and Outlook 2019 client to log users into their e-mails automatically? This works perfectly fine in Internet Explorer. I've gone through the following guides: https://docs.microsoft.com/en-gb/azure/active-directory/hybrid/how-to-connect-sso-quick-start https://docs.microsoft.com/en-gb/azure/active-directory/hybrid/tshoot-connect-sso https://docs.microsoft.com/en-GB/sharepoint/troubleshoot/administration/troubleshoot-mapped-network-drives https://docs.microsoft.com/en-gb/azure/active-directory/hybrid/how-to-connect-sso-faq I must be missing something.
FN-GM Posted September 16, 2021 Posted September 16, 2021 Are you using the custom URL? eg: https:outlook.com/domain.com
Chuckster Posted September 16, 2021 Author Posted September 16, 2021 I tried the custom URL and it still requests users to enter their e-mail address, after which they then proceed to log in without having to enter their password. In Internet Explorer, users can simply go to https://www.office.com and it will log them in automatically without them having to enter their e-mail address.
willtech Posted September 16, 2021 Posted September 16, 2021 Have you got: https://autologon.microsoftazuread-sso.com in the intranet zone ?
Chuckster Posted September 16, 2021 Author Posted September 16, 2021 These are the entries I have in my screenshot.
willtech Posted September 16, 2021 Posted September 16, 2021 Thats odd should normally work. as your setting is correct. When you try the custom URL does it briefly say trying to sign you in then go to the sign in screen ?
Chuckster Posted September 16, 2021 Author Posted September 16, 2021 It doesn't say it's briefly signing me in. It goes striaght to the page where you need to enter your e-mail address. Once you have entered that in it will then proceed. IE, on the other hand, works seemlessly.
RobD Posted September 16, 2021 Posted September 16, 2021 Is your upn the same as your email? If not then that could get in the way???
Chuckster Posted September 16, 2021 Author Posted September 16, 2021 The UPN suffix is identical to the e-mail address. Any one care to share their Edge and Chrome GPO as well as their Outlook?
Boredguy Posted September 16, 2021 Posted September 16, 2021 Like the others above, just got the sites in the IE Site to Zone assignment, but all of our workstations are also set as Hybrid Azure AD devices with the option set in AzureConnect and in GPO (see below) User Policy Windows Componets\Internet Explorer\Internet Control Panel\Security Page\Site to Zone Assignment List https://autologon.microsoftazuread-sso.com 1 https://aadg.windows.net.nsatc.net 1 https://tenancyname-my.sharepoint.com 1 https://tenancyname.sharepoint.com 1 Workstation Policy Windows Componets\Internet Explorer\Internet Control Panel\Security Page\Site to Zone Assignment List https://device.login.microsoftonline.com 1 Windows Componets\Device Registration Register Domain Joined Computers as Devices Enabled
Chuckster Posted September 21, 2021 Author Posted September 21, 2021 @Boredguy, I have the exact same settings but still getting nowhere with it.
kevin_lane Posted September 21, 2021 Posted September 21, 2021 what settings have you got for the ad sync application
DeMoB Posted December 5, 2022 Posted December 5, 2022 Thats odd should normally work. as your setting is correct. When you try the custom URL does it briefly say trying to sign you in then go to the sign in screen ? Sorry to necromance this thread, but I'm running into this same issue, and the only difference I've seen is that I'm experiencing the brief "trying to sign you in" screen before and wondered if there was anything to unpick here? ADFS debug logging (admittedly on basic) didn't appear to show an entry for this, and the domain hint only takes it to the adfs logon page.
chaplic Posted December 5, 2022 Posted December 5, 2022 ADFS is a different kettle of fish (firstly why ADFS, but dealing with the matter in hand) What happens when you call https:///adfs/ls/IdpInitiatedSignon.aspx You should be able to sign in here without putting U&P. It if doesnt you need that URL in your intranet zone.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now