Jump to content

Recommended Posts

Posted

Wonder if anyone else has seen this?

 

We've been successully using Microsoft accounts to SSO onto our Chromebooks. Works fine - enter username and password, on you go.

 

Until this week. It just started looping back to the login screen. Checked the services portal - fault with some applications, so waited for that to be fixed. No change.

 

Now started into the black hole of changing how SSO works on them. I have setup and approved OIDC (Open ID Connector) instead of the old application setup, which should be good, but now we just get 'cannot verify that this account is yours'. Kind of makes sense - we're trying to get into the same accounts with a different credential provider now.

 

Thankfully my admin accounts were not included in the SSO scope, so I can get into Google Workspace. No one else can.

 

Any ideas?

Posted

Have you checked filtering?  Try one on an unfiltered connection and see if the problem persists, we get this sometimes, they change the urls that need to bypass filtering.  

Posted

Weirdly mine is working and I am not using OIDC, I did have to change a SSO setting in the Entra ID Application to use UPN rather than email, due to historical reasons though

image.thumb.png.e4f2ae9077a5b5500a9cf319d314d38b.png

Posted

I'm now in with a test user.

 

Couple of things:

I've changed to OIDC rather than legacy. Legacy stopped working for the above reason - the Unique User Identifier was set as user.mail and this stopped working for us very recently (login loop) for all users.

 

The test user I was using had a correctly formed UPN field, but no email address set in AD. Grrrrr. Only spotted that in Entra. Tested back with another user and it let me in.

 

OIDC isn't as slick on desktop now - when I click on the Google Workspace icon in the Micorosoft 365 portal it doesn't go straight in, but asks for the email address again (not the password). I suspect this is a quirk with the redirect URL in Entra but it's a turnkey solution and you can't easily edit anything.

I've actually kept the old legacy SAML application running in Entra because if I disable it, users sometimes can't log on to ChromeOS. Might be solved if I delete that application but I'd rather not!

  • 4 months later...
Posted

@mjhardisty Sorry to hear you have had issues with Exa around the Chromebook sign-in via Entra.

 

I have been looking at a ticket that was raised with us in January, which I believe is one of your schools, and I can confirm that we are still investigating the root cause of the problem, which is that Google does not like it when traffic to www.google.com is decrypted, which breaks the communications and results in the sign-in failing. But if we stop decrypting this, then keyword filtering on Google search pages would be redundant.

 

If you would like to discuss this issue further, please feel free to get back in touch with our Helpdesk via email ([email protected]), or you can email me directly ([email protected])

 

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...