Azure AD Seamless SSO and Teams error

DavidM 0 Reputation points
2024-11-11T08:18:40.6333333+00:00

We have successfully enabled seamless SSO in our Active Directory - Microsoft Entra ID environment by following Microsoft's quickstart guide (https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sso-quick-start) and tested it by browsing to https://myapps.microsoft.com/ourdomain.onmicrosoft.com. Test was successful and we are automatically logged in.

The problem we actually have is that we can't auto sign on Microsoft Teams or any other office desktop apps (Word, Excel...).

Speaking about Teams, we've installed it by downloading teamsbootstrapper.exe (https://go.microsoft.com/fwlink/?linkid=2243204&clcid=0x409) and running .\teamsbootstrapper.exe -p. Teams successfully opens but it always prompts for user and password.

When it comes to Word or any other office desktop app, we actually see user's information in the top right corner of Word's starting page, and when we browse into Open from OneDrive, we can click the "Sign on" button. Once we've clicked it, we get prompted to select an account to log into OneDrive and we select current logged in user's account, but the prompt just closes and nothing happens.

Things that we already did/check:

  • Configure GPO to set up intranet sites, setting up "https://autologon.microsoftazuread-sso.com" and "https://teams.microsoft.com" to be part of it.
  • Configure all other GPO values mentioned in quickstart guide.
  • Reinstall Teams.
  • Clear teams temporal files
  • Ensure that the GPO is correctly applied
  • Navigate to https://myapps.microsoft.com/ourdomain.onmicrosoft.com to check that the user doesn't have to enter nor username or password.
  • Navigate to https://portal.office.com to check that user only has to write down the username.

Our machines are running:

  • Windows 10 22H2
  • Latest Teams version (recently downloaded it)
  • Word is part of the Microsoft Office Professional Plus 2019 suite.

Thanks beforehand!

Azure Data Factory
Azure Data Factory
An Azure service for ingesting, preparing, and transforming data at scale.
11,639 questions
Microsoft Teams | Microsoft Teams for business | Other
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2024-12-12T14:44:29.7066667+00:00

    I personally recommend you do not enable Seamless SSO:

    https://trustedsec.com/blog/azure-ad-kerberos-tickets-pivoting-to-the-cloud

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.