clareq Posted December 7, 2022 Posted December 7, 2022 I have determined that my IE to Zone allocation GPO is preventing office add-ins from working. Do I still need to make sites "trusted" for SSO to 365 to work?
clareq Posted December 7, 2022 Author Posted December 7, 2022 Strange - as a test I removed the policy, cleared my test user profile and logged in. SSO worked. The GPO I had used to set Trusted Sites had been in place for some years, but the add-ins only started failing recently. I wonder if something has been changed at microsoft's end. I can't find a definitive up to date list of URLs I need to trust.
chaplic Posted December 7, 2022 Posted December 7, 2022 I remember back in the day a similar issue as Microsoft added a url microsoftonline-p.com to their URLs involved with login, the MS engineer I spoke to reckoned if you dont have ADFS then it doesnt matter what zone things are in as long as they are consistent. So I'd try removing all zone entries and see how that behaves then you've removed a future headache.
clareq Posted December 7, 2022 Author Posted December 7, 2022 I have done - I'll keep an eye on any log in issues, but my tests seem OK so far.
KK20 Posted December 7, 2022 Posted December 7, 2022 you need to make autologon.microsoftazuread-sso.com trusted so that you can pass the kerberos tickets to an internet/cloud site. Unless you have your security set so low that any internet site can request (!!). Im not sure if you actually need any other sites setting to trusted for SSO to work, we certainly dont have many in our zone allocation. Ive seen people putting *.office.com and *.sharepoint.com in there, we certainly havent.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now