<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SSO | KC's Blog</title>
	<atom:link href="https://www.kjctech.net/tag/sso/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kjctech.net</link>
	<description></description>
	<lastBuildDate>Tue, 24 Jan 2023 18:20:52 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://i0.wp.com/www.kjctech.net/wp-content/uploads/2016/12/cropped-KC-Logo.png?fit=32%2C32&#038;ssl=1</url>
	<title>SSO | KC's Blog</title>
	<link>https://www.kjctech.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">24634607</site>	<item>
		<title>Configuring Azure Active Directory Single Sign-On (SSO) with Azure AD Connect</title>
		<link>https://www.kjctech.net/configuring-azure-active-directory-single-sign-on-sso-with-azure-ad-connect/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=configuring-azure-active-directory-single-sign-on-sso-with-azure-ad-connect</link>
					<comments>https://www.kjctech.net/configuring-azure-active-directory-single-sign-on-sso-with-azure-ad-connect/#respond</comments>
		
		<dc:creator><![CDATA[Kent Chen]]></dc:creator>
		<pubDate>Mon, 17 Jan 2022 07:06:47 +0000</pubDate>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Azure AD Connect]]></category>
		<category><![CDATA[SSO]]></category>
		<guid isPermaLink="false">https://www.kjctech.net/?p=4710</guid>

					<description><![CDATA[<p>If you haven&#8217;t synced your local Active Directory to Microsoft 365 via Azure Cloud Connect, you can start here. If you have but haven&#8217;t enabled SSO to simplify the process, you are missing out on something big. With Azure AD SSO, you don&#8217;t have to type in your passwords to sign in to Azure AD, and most of the time, [&#8230;]</p>
The post <a href="https://www.kjctech.net/configuring-azure-active-directory-single-sign-on-sso-with-azure-ad-connect/">Configuring Azure Active Directory Single Sign-On (SSO) with Azure AD Connect</a> first appeared on <a href="https://www.kjctech.net">KC's Blog</a>.]]></description>
										<content:encoded><![CDATA[<p>If you haven&#8217;t synced your local Active Directory to Microsoft 365 via Azure Cloud Connect, you can start <a href="https://www.kjctech.net/setting-up-directory-sync-between-on-premises-active-directory-with-microsoft-365-azure-ad/" title="here" target="_blank" rel="noreferrer noopener">here</a>. If you have but haven&#8217;t enabled SSO to simplify the process, you are missing out on something big.</p>



<p>With Azure AD SSO, you don&#8217;t have to type in your passwords to sign in to Azure AD, and most of the time, you don&#8217;t even need to type the username. You log into a domain-joined computer with your own credential and that&#8217;s all you need to get all apps ready, including Edge, Office apps, and Teams.</p>



<p>Open Azure AD Connect, click <strong>Configure,</strong> then <strong>Change user sign-in</strong> option, and go Next.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="600" height="416" src="//i0.wp.com/kjctech.net/wp-content/uploads/2022/01/image-4-600x416.png" alt="" class="wp-image-4711" srcset="https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-4.png?resize=600%2C416&amp;ssl=1 600w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-4.png?resize=450%2C312&amp;ssl=1 450w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-4.png?resize=250%2C173&amp;ssl=1 250w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-4.png?resize=700%2C486&amp;ssl=1 700w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-4.png?resize=520%2C361&amp;ssl=1 520w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-4.png?resize=360%2C250&amp;ssl=1 360w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-4.png?resize=100%2C69&amp;ssl=1 100w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-4.png?w=715&amp;ssl=1 715w" sizes="(max-width: 600px) 100vw, 600px" /></figure>



<p>Sign in with your Office 365 Global Admin credential, and then check <strong>Enable single sign-on</strong> option.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="600" height="246" src="//i0.wp.com/kjctech.net/wp-content/uploads/2022/01/image-5-600x246.png" alt="" class="wp-image-4712" srcset="https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?resize=600%2C246&amp;ssl=1 600w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?resize=450%2C185&amp;ssl=1 450w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?resize=250%2C103&amp;ssl=1 250w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?resize=768%2C315&amp;ssl=1 768w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?resize=700%2C287&amp;ssl=1 700w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?resize=520%2C214&amp;ssl=1 520w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?resize=360%2C148&amp;ssl=1 360w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?resize=100%2C41&amp;ssl=1 100w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-5.png?w=879&amp;ssl=1 879w" sizes="(max-width: 600px) 100vw, 600px" /></figure>



<p>You will need to type a Domain Admin credential as well to finish the process.</p>



<p>Once the sync is finished, you can check the Azure AD to make sure if the single sign-on is enabled.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="600" height="259" src="//i0.wp.com/kjctech.net/wp-content/uploads/2022/01/image-6-600x259.png" alt="" class="wp-image-4713" srcset="https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?resize=600%2C259&amp;ssl=1 600w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?resize=450%2C194&amp;ssl=1 450w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?resize=250%2C108&amp;ssl=1 250w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?resize=768%2C332&amp;ssl=1 768w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?resize=700%2C302&amp;ssl=1 700w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?resize=520%2C224&amp;ssl=1 520w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?resize=360%2C155&amp;ssl=1 360w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?resize=100%2C43&amp;ssl=1 100w, https://i0.wp.com/www.kjctech.net/wp-content/uploads/2022/01/image-6.png?w=871&amp;ssl=1 871w" sizes="(max-width: 600px) 100vw, 600px" /></figure>



<p>Next step is to add the following URL in the Intranet Zone via Group Policy.</p>



<pre class="wp-block-preformatted"><code>https://autologon.microsoftazuread-sso.com</code></pre>



<p>The policy is called <strong>Site to Zone Assignment list </strong>under</p>



<pre class="wp-block-preformatted">User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page</pre>



<p>While we are here, let&#8217;s also enable <strong>Allow updates to status bar via script</strong> under <strong>Intranet Zone</strong></p>



<p>Finally, if you are using the new Edge browser, add the same Azure AD&#8217;s URL to the <strong>Specifies a list of servers that Microsoft Edge can delegate user credentials</strong> to the following place.</p>



<pre class="wp-block-preformatted">User Configuration > Administrative Templates > Microsoft Edge > HTTP authentication</pre>



<p>That&#8217;s about as simple as I can put out. If all goes well, it does work like a charm. </p>



<h3 class="wp-block-heading">Resources</h3>



<p><a href="https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-how-it-works">Azure AD Connect: Seamless Single Sign-On &#8211; How it works | Microsoft Docs</a></p>



<p><a href="https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start">Azure AD Connect: Seamless Single Sign-On &#8211; quickstart | Microsoft Docs</a></p>



<p></p>The post <a href="https://www.kjctech.net/configuring-azure-active-directory-single-sign-on-sso-with-azure-ad-connect/">Configuring Azure Active Directory Single Sign-On (SSO) with Azure AD Connect</a> first appeared on <a href="https://www.kjctech.net">KC's Blog</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.kjctech.net/configuring-azure-active-directory-single-sign-on-sso-with-azure-ad-connect/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4710</post-id>	</item>
	</channel>
</rss>
