Manny-Tech Posted March 22, 2023 Posted March 22, 2023 Hi, I'm having issues getting OneDrive automatically signing in on our domain joined Windows 10 clients on 21H2. I have AAD Connect configured with Passthrough Authentication enabled, I can verify this is working by signing into O365 seamlessly. I have also installed the latest OneDrive ADM files to Group Policy, configured my tenant ID, and other relevant settings to silently configure OneDrive. The problem I'm experiencing is that on some devices it works flawlessly, and on others it launches OneDrive, updates, but never actually signs in and prompts for users email address. Though on said machines where it doesn't work I can verify that SSO is working to O365 platform. There doesn't appear to be much in the way of log files. Has anyone else come across this or has any pointers on how to resolve? Thanks
tangotech Posted March 23, 2023 Posted March 23, 2023 Make sure the computers are included in the AAD sync.
Manny-Tech Posted March 23, 2023 Author Posted March 23, 2023 Is that a requirement? I have a lot of computers that aren't, but they still silently sign in?
Boredguy Posted March 23, 2023 Posted March 23, 2023 We use registry settings in our users GPO to do the silent login for OneDrive Policy settings (including the registry settings) are in zip in this thread here -> http://www.edugeek.net/forums/how-do-you-do/216456-microsoft-onedrive-365-a.html
chaplic Posted March 23, 2023 Posted March 23, 2023 Is that a requirement? I have a lot of computers that aren't, but they still silently sign in? Im too lazy to check, but yes that was the first thing I thougt of, hybrid join is a requirement. It might also be a portent of you have failing TPMs...
DavR Posted March 23, 2023 Posted March 23, 2023 If it's certain computers that OneDrive won't SSO on, then yes I would echo the hybrid join theory. Hybrid AAD join is defo required for computers. If it's certain user accounts, might need to check that the UPN is definitely correct. Possibly also you might need email address in the email field in AD, although that could just be a requirement for Outlook.
Manny-Tech Posted March 27, 2023 Author Posted March 27, 2023 I have computers sync'ing via AAD Connect, still no luck. I haven't hybrid joined any device as yet, so I'm not sure that is a contributing factor, especially based on having other machines working fine. I did flatten one of the devices today with a fresh install and it now does the silent config everytime. I was rather hoping that wouldn't solve it because that's not something I want to do on 200+ machines. Though if it's a necessity then so be it I guess.
DavR Posted March 28, 2023 Posted March 28, 2023 If you're syncing computers via AAD Connect, then they should be doing a hybrid domain join silently in the background. It happens by a Scheduled Task that runs in the background, and may not be immediate. Have a look in your AAD console and see if computer accounts have started appearing. If they've not, then it's the background AAD hybrid domain join that you need to look at. Fingers crossed you can find an answer on this that isn't a site wide rebuild!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now