Jump to content

Recommended Posts

Posted

Hii

 

I hope I have posted this in the correct section as all our clients are Windows 11

 

Our IT Teacher wants single sign on for OneDrive.

 

- I have followed the procces step by step from Microsoft here https://learn.microsoft.com/en-us/sharepoint/use-group-policy#SilentAccountConfig

- Added the registry keys though group policy and tried adding manually

- I have joined the PC to Azure AD using the hybrid configuration

 

When a student logs in, it prompts them to setup onedrive, asking for a email address. When they type their email address, it logs them straight in not even asking for a password and will remain logged in if the student revisits the same PC but when they use another PC, it prompts them to login which frustrates the IT teacher.

 

SSO works fine with edge, office applications, Teams but onedrive is the only application that prompts for a email. I know I am missing something, I just dont know what.

 

Any help is appreciated - Thankyou :-)

Posted

HI thimon

 

Thankyou, would you mind screenshotting your group policy settings if thats OK. This is the group policy we have enabled for computer configuration and user configuration:

 

Computer Configuration (Enabled Policies)

Administrative Templates - Microsoft Office 2016 (Machine)/Licensing Settings

 

Enable EDU Org ID Sign In in Office from Windows Store: Enabled

Use shared computer activation: Enabled

 

Administrative Templates - OneDrive

 

Always use the user's Windows display language when provisioning known folders in OneDrive: Enabled

Prevent users from moving their Windows known folders to OneDrive: Enabled

Prevent users from redirecting their Windows known folders to their PC: Enabled

Set the sync app update ring: Deferred

Silently move Windows known folders to OneDrive: Enabled

Tenant ID: xxxxx

Folder Options: Desktop, Documents, Pictures

Silently sign in users to the OneDrive sync app with their Windows credentials: Enabled

Specify the OneDrive location in a hybrid environment: Enabled

Authenticate first against: SharePoint Online

Use OneDrive Files On-Demand: Enabled

 

Administrative Templates - Windows Components/Device Registration

 

Register domain joined computers as devices: Enabled

 

Administrative Templates - Windows Components/Internet Explorer/Internet Control Panel/Security Page

 

Site to Zone Assignment List: Enabled

Zone Assignments:

https://device.login.microsoftonline.com (1)

https://login.microsoftonline.com (1)

https://aadg.windows.net.nsatc.net (1)

 

Administrative Templates - Windows Components/OOBE

 

Don't launch privacy settings experience on user logon: Enabled

 

User Configuration (Enabled Policies)

Administrative Templates - Microsoft Office 2016/Miscellaneous

 

Suppress recommended settings dialog: Enabled

 

Administrative Templates - Microsoft Office 2016/Privacy/Trust Center

 

Allow Microsoft to follow up on feedback submitted by users: Disabled

Allow the use of connected experiences in Office that analyze content: Disabled

Allow users to submit feedback to Microsoft: Disabled

Disable Opt-in Wizard on first run: Enabled

Enable Customer Experience Improvement Program: Disabled

Send personal information: Disabled

 

Administrative Templates - Microsoft Office 2016/Subscription Activation

 

Automatically activate Office with federated organization credentials: Enabled

 

Administrative Templates - OneDrive

 

Allow users to choose how to handle Office file sync conflicts: Enabled

Always use the user's Windows display language when provisioning known folders in OneDrive: Enabled

Coauthor and share in Office desktop apps: Enabled

Continue syncing on metered networks: Enabled

Continue syncing when devices have battery saver mode turned on: Enabled

Disable the tutorial that appears at the end of OneDrive Setup: Enabled

Prevent users from syncing personal OneDrive accounts: Disabled

 

Administrative Templates - Windows Components/Internet Explorer/Internet Control Panel/Security Page

 

Site to Zone Assignment List: Enabled

Zone Assignments:

https://autologon.microsoftazuread-sso.com (1)

*.sharepoint.com (1)

*.onedrive.com (1)

 

Administrative Templates - Windows Components/Windows Hello for Business

 

Use Windows Hello for Business: Enabled

Do not start Windows Hello provisioning after sign-in: Enabled

  • Thanks 1
Posted

If it's prompting them to login, but SSO succeeds after that, I wonder if it's getting the login username correctly?

 

IIRC, we needed to have the user's email address, in the email field in users AD account, before OneDrive would sign in silently.

Posted

Thank you thimon

 

DavR thanks that's a good shout. I did check the domain and it is matching with what I have in azure. The students have their full email address in the email field although I will check the attributes in the morning.

Posted
Thanks 2097, I have checked all enforced GPOs and cant see anything obvious. I also used the policy analyser tool. I am using pass-through authentication with SSO enabled. I will keep trying
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...