Enable Windows Seamless SSO on Windows Domain-Joined Workstations

Jeoffrey NGO 0 Reputation points
2025-02-10T20:48:18.9633333+00:00

I am using Microsoft Entra ID Cloud Sync to synchronize user accounts from three organizational units with EntraID. The password and other parameters are correctly synced from on-premises to Entra ID. However, devices are not synchronized from on-premises to the cloud as I am using Microsoft Entra ID Cloud Sync and not Microsoft Entra Connect Sync. The Windows Servers are running on Windows Server 2016, and all users have Microsoft 365 Business Standard licenses, which prevents hybrid device enrollment.

I aim to enable seamless SSO for Windows users to access Microsoft Teams, Office 365, and other portals like portal.microsoft.com without needing to enter their usernames or passwords. I have enabled SSO on Entra Cloud Sync using the procedure from Microsoft's documentation and verified its status via PowerShell and the Azure portal. The computer account AZUREADSSOACC was created correctly, and I have also created the necessary GPO (https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sso-quick-start).

Despite these steps, seamless SSO is not working on my test workstation, which is domain-joined and running Windows 11. Users are still prompted for their usernames and passwords. The klist command does not list the AZUREADSSOACC server. The device has a direct connection to the domain controllers. The GPOS has been rolled out to the user. The device's time is synchronized with the time in both Active Directory and the domain controllers. The account AZUREADSSOACC is enabled and present in the Active Directory. The klist get AZUREADSSOACC works and add the AZUREADSSOACC in the klist command but SSO still doesn not work.

Did I do something wrong ? Does Microsoft Entra hybrid joined devices is required when using Microsoft Entra ID Cloud Sync ?

Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
2,258 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,824 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 153.8K Reputation points MVP
    2025-02-11T11:38:51.42+00:00

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.