{"id":12181,"date":"2017-07-13T08:24:00","date_gmt":"2017-07-13T08:24:00","guid":{"rendered":"https:\/\/viewmyprojects.com\/winwirewp\/?p=12181"},"modified":"2025-01-28T09:27:39","modified_gmt":"2025-01-28T09:27:39","slug":"azure-ad-connect-sso","status":"publish","type":"post","link":"https:\/\/viewmyprojects.com\/winwirewp\/blog\/azure-ad-connect-sso\/","title":{"rendered":"How to Set up Azure AD Connect SSO"},"content":{"rendered":"\n<p>Ever since the launch of Office 365, there has been a need to make these services seamlessly accessible. Needless to say that Single Sign On (SSO) has been on the top requirement list for many organizations.<\/p>\n\n\n\n<p><em>I wanted to put together a quick post and run through how easy it is to setup Single Sign On and enhance the user experience.<\/em><\/p>\n\n\n\n<p><strong>Azure Active Directory Connect makes Single Sign-On Easy<br><\/strong><br>Azure AD Connect includes a new capability-&nbsp;<strong>Single Sign-On<\/strong>. The feature enables organizations to implement SSO with both cloud &amp; on-prem based applications without requiring any additional server configurations.<\/p>\n\n\n\n<p class=\"blog-detail-list\">SSO can be combined with either of the below two Sync options:<br>\u2022 Password Hash Synchronization (Agent Less)<br>\u2022 Pass-through Authentication<\/p>\n\n\n\n<p>Setting up this service is simple and easy, and done from the AAD Connect tool. Below are the steps that take you through this process<\/p>\n\n\n\n<p class=\"blog-detail-list\">\u2022 Add the below 2 URLS into the Intranet Zone via GPO<br>https:\/\/autologon.microsoftazuread-sso.com<br>https:\/\/aadg.windows.net.nsatc.net<\/p>\n\n\n\n<p class=\"blog-detail-list\">\u2022 Launch AAD Connect and click on the Change User Sign-in<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"628\" height=\"448\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad1.webp\" alt=\"\" class=\"wp-image-18671\" srcset=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad1.webp 628w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad1-300x214.webp 300w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"629\" height=\"442\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad2.webp\" alt=\"\" class=\"wp-image-18670\" srcset=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad2.webp 629w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad2-300x211.webp 300w\" sizes=\"auto, (max-width: 629px) 100vw, 629px\" \/><\/figure><\/div>\n\n\n<p><strong>Enter Global Administrator credentials<br><\/strong><\/p>\n\n\n\n<p>The below screen you will be presented with 3 Options, you can use all of them to enable SSO. However, each of these methods has their own advantages:<\/p>\n\n\n\n<p class=\"blog-detail-list\">\u2022&nbsp;<strong>Password Synchronization<\/strong>: In this method, password hashes are synced with Azure AD.<br>(Server &amp; Agentless SSO)<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"210\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad3.webp\" alt=\"\" class=\"wp-image-18669\"\/><\/figure><\/div>\n\n\n<p class=\"blog-detail-list\">\u2022&nbsp;<strong>Pass-Through Authentication<\/strong>: Like the first option, however, the password hashes are not synced with Azure AD. However, this method requires a lightweight agent to be installed on-premises (this service is still in preview while this article was written)<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"464\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad4-1024x464-1.webp\" alt=\"\" class=\"wp-image-18668\" srcset=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad4-1024x464-1.webp 1024w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad4-1024x464-1-300x136.webp 300w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad4-1024x464-1-768x348.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p class=\"blog-detail-list\">\u2022&nbsp;<strong>Federation with AD FS:<\/strong>&nbsp;This method requires a full-fledged deployment of ADFS farm to enable SSO with using the Federation Service<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"502\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad5-1024x502-1.webp\" alt=\"\" class=\"wp-image-18667\" srcset=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad5-1024x502-1.webp 1024w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad5-1024x502-1-300x147.webp 300w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad5-1024x502-1-768x377.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p>We have selected password hash Sync, to enable Seamless SSO as shown below<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"215\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad6.webp\" alt=\"\" class=\"wp-image-18666\"\/><\/figure><\/div>\n\n\n<p>Click on next and complete the configuration<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"629\" height=\"447\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad7.webp\" alt=\"\" class=\"wp-image-18665\" srcset=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad7.webp 629w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad7-300x213.webp 300w\" sizes=\"auto, (max-width: 629px) 100vw, 629px\" \/><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"629\" height=\"445\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad8.webp\" alt=\"\" class=\"wp-image-18663\" srcset=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad8.webp 629w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad8-300x212.webp 300w\" sizes=\"auto, (max-width: 629px) 100vw, 629px\" \/><\/figure><\/div>\n\n\n<p>Wait for the wizard to complete and show the Configuration Completed Message as shown below<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"628\" height=\"444\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad9.webp\" alt=\"\" class=\"wp-image-18664\" srcset=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad9.webp 628w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/aad9-300x212.webp 300w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><\/figure><\/div>\n\n\n<p class=\"blog-detail-list\"><strong>Validation<\/strong>:<br>The below Steps can be followed to validate if the deployment has been successful<br>\u2022 Look for any Authentication errors in the Azure AD portal<br>\u2022 Look up the local AD for a&nbsp;<strong>Computer Account<\/strong>&nbsp;\u201cAZUREADSSOACT\u201d<br>\u2022 Run the below PowerShell command and confirm the domain has been enabled for SSO<br><em>GET-AZUREAADSSOSTATUS<\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"587\" height=\"57\" src=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/ade10.webp\" alt=\"\" class=\"wp-image-18662\" srcset=\"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/ade10.webp 587w, https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/ade10-300x29.webp 300w\" sizes=\"auto, (max-width: 587px) 100vw, 587px\" \/><\/figure><\/div>\n\n\n<p><strong>Advantages of AAD connect SSO<\/strong><\/p>\n\n\n\n<p class=\"blog-detail-list\">\u2022 It\u2019s a Free Service, which Doesn\u2019t require additional licenses or premium subscriptions of Azure AD<br>\u2022 Serverless deployment of SSO solution<br>\u2022 Works with either Password Sync or Pass-through Authentication<br>\u2022 Unlike ADFS, this solution can be rolled out to users on need basis<br>\u2022 Ease of Administration of both Directory Sync and SSO<\/p>\n\n\n\n<p><em><strong>In Conclusion<br><\/strong><\/em><br><em>There is a lot of useful documentation available about AAD Connect on the Microsoft website, I highly recommend that you check it out as well:<\/em><\/p>\n\n\n\n<p><em>https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/connect\/active-directory-aadconnect-sso<\/em><br><em>https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/connect\/active-directory-aadconnect-sso-quick-start<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ever since the launch of Office 365, there has been a need to make these services seamlessly accessible. Needless to say that Single Sign On (SSO) has been on the top requirement list for many organizations. I wanted to put together a quick post and run through how easy it is to setup Single Sign&hellip; <a class=\"more-link\" href=\"https:\/\/viewmyprojects.com\/winwirewp\/blog\/azure-ad-connect-sso\/\">Continue reading <span class=\"screen-reader-text\">How to Set up Azure AD Connect SSO<\/span><\/a><\/p>\n","protected":false},"author":32,"featured_media":16685,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_eb_attr":"","_uag_custom_page_level_css":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-12181","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","entry"],"acf":[],"featured_image_src":"https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic.webp","author_info":{"display_name":"Sai","author_link":"https:\/\/viewmyprojects.com\/winwirewp\/author\/sai\/"},"views":3661,"uagb_featured_image_src":{"full":["https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic.webp",800,440,false],"thumbnail":["https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic-150x150.webp",150,150,true],"medium":["https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic-300x165.webp",300,165,true],"medium_large":["https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic-768x422.webp",750,412,true],"large":["https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic.webp",750,413,false],"1536x1536":["https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic.webp",800,440,false],"2048x2048":["https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic.webp",800,440,false],"post-thumbnail":["https:\/\/viewmyprojects.com\/winwirewp\/wp-content\/uploads\/2023\/11\/How-to-Set-up-Azure-AD-Connect-SSO-graphic.webp",800,440,false]},"uagb_author_info":{"display_name":"Sai","author_link":"https:\/\/viewmyprojects.com\/winwirewp\/author\/sai\/"},"uagb_comment_info":0,"uagb_excerpt":"Ever since the launch of Office 365, there has been a need to make these services seamlessly accessible. Needless to say that Single Sign On (SSO) has been on the top requirement list for many organizations. I wanted to put together a quick post and run through how easy it is to setup Single Sign&hellip;&hellip;","_links":{"self":[{"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/posts\/12181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/users\/32"}],"replies":[{"embeddable":true,"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/comments?post=12181"}],"version-history":[{"count":3,"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/posts\/12181\/revisions"}],"predecessor-version":[{"id":22511,"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/posts\/12181\/revisions\/22511"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/media\/16685"}],"wp:attachment":[{"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/media?parent=12181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/categories?post=12181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/viewmyprojects.com\/winwirewp\/wp-json\/wp\/v2\/tags?post=12181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}