We're trying to deploy Office applications to a Citrix VDI environment, using Shared Computer Activation. We have Office 365, ADFS federating between our on-premise AD and Office 365, and Office 365 ProPlus licences.
When a user first opens an Office application, they are asked to sign in. The user then gets a screen "Use this account everywhere on your device" with a checkbox "Allow my organisation to manage my device" and only one button to proceed: "Yes". You have to
click "Yes" and leave the checkbox ticked in order to proceed otherwise Office doesn't end up licensed (so what's the point of this screen?). After 3 minutes or so, while the message is "Hold on while we register this device with your company and apply the
policy" then you get the Organisation sign-in page again where you have to enter your password (again). Then a screen "Something went wrong. We weren't able to register your device and add your account to Windows. Your access to org resources may be limited".
Then finally after this: Office signs in and registers!
What's happening seems to be related to Azure AD Join/Register for the computer, as under Office 365 Admin > Azure AD > Devices settings you can see all the permutations of VDI computers and users who have signed in to Office registered as devices! But we are
not trying to use Azure AD Join or Register, Office 365 device management is turned off and Intune has no policies. So why is Office trying to do this? It's a terrible/broken user experience and it will populate literally thousands of pointless devices in
Azure AD once we roll VDI out beyond test users. Am I missing some key setting here that makes Office just do simple Shared Computer Activation as documented?
Thanks