data:image/s3,"s3://crabby-images/733b2/733b2ac421984f8da9a32ff172d522b177f2984b" alt="..."
Ever since the launch of Office 365, there has been a need to make these services seamlessly accessible. Needless to say that Single Sign On (SSO) has been on the top requirement list for many organizations.
I wanted to put together a quick post and run through how easy it is to setup Single Sign On and enhance the user experience.
Azure Active Directory Connect makes Single Sign-On Easy
Azure AD Connect includes a new capability- Single Sign-On. The feature enables organizations to implement SSO with both cloud & on-prem based applications without requiring any additional server configurations.
SSO can be combined with either of the below two Sync options:
• Password Hash Synchronization (Agent Less)
• Pass-through Authentication
Setting up this service is simple and easy, and done from the AAD Connect tool. Below are the steps that take you through this process
• Add the below 2 URLS into the Intranet Zone via GPO
https://autologon.microsoftazuread-sso.com
https://aadg.windows.net.nsatc.net
• Launch AAD Connect and click on the Change User Sign-in
data:image/s3,"s3://crabby-images/7fd72/7fd721359f02a29351edd578efec32d167c5a453" alt=""
data:image/s3,"s3://crabby-images/3317d/3317d9ff7e9ec30aa7747775fdd0d094fdb56860" alt=""
Enter Global Administrator credentials
The below screen you will be presented with 3 Options, you can use all of them to enable SSO. However, each of these methods has their own advantages:
• Password Synchronization: In this method, password hashes are synced with Azure AD.
(Server & Agentless SSO)
data:image/s3,"s3://crabby-images/6fa0d/6fa0d9aa3685f8479b91fa6c8119465392623702" alt=""
• Pass-Through Authentication: Like the first option, however, the password hashes are not synced with Azure AD. However, this method requires a lightweight agent to be installed on-premises (this service is still in preview while this article was written)
data:image/s3,"s3://crabby-images/6f484/6f4842d0f55c54575c25988793f3733ec8c4748d" alt=""
• Federation with AD FS: This method requires a full-fledged deployment of ADFS farm to enable SSO with using the Federation Service
data:image/s3,"s3://crabby-images/cb422/cb4228cd9709a41cd58c414cc3e30405fd885ba0" alt=""
We have selected password hash Sync, to enable Seamless SSO as shown below
data:image/s3,"s3://crabby-images/597b0/597b01b5450bf73d1ae71839516b0d49d2251b41" alt=""
Click on next and complete the configuration
data:image/s3,"s3://crabby-images/83621/8362162a8121d275172d2ece5ee3ce41170ab465" alt=""
data:image/s3,"s3://crabby-images/9102d/9102d9fac165ffd94cc2488d9430c61f00b79f30" alt=""
Wait for the wizard to complete and show the Configuration Completed Message as shown below
data:image/s3,"s3://crabby-images/43daf/43daf4d0e8114438aeac749968c4abe472c77f06" alt=""
Validation:
The below Steps can be followed to validate if the deployment has been successful
• Look for any Authentication errors in the Azure AD portal
• Look up the local AD for a Computer Account “AZUREADSSOACT”
• Run the below PowerShell command and confirm the domain has been enabled for SSO
GET-AZUREAADSSOSTATUS
data:image/s3,"s3://crabby-images/77340/77340a4ccf7f74e8768cf612ec56fecfd48be7af" alt=""
Advantages of AAD connect SSO
• It’s a Free Service, which Doesn’t require additional licenses or premium subscriptions of Azure AD
• Serverless deployment of SSO solution
• Works with either Password Sync or Pass-through Authentication
• Unlike ADFS, this solution can be rolled out to users on need basis
• Ease of Administration of both Directory Sync and SSO
In Conclusion
There is a lot of useful documentation available about AAD Connect on the Microsoft website, I highly recommend that you check it out as well:
https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso
https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start