Azure AD SSO Query

Chalee 12 Reputation points

Hi all,

We have on prem AD which we sync to Azure AD using AD connect and this seems to be working OK. We have created an Enterprise App in Azure for an externally hosted app and configured SSO. This works fine for users on a domain joined device.

If I try and access the app on a non domain joined device I get to the MS sign-on page and enter my email address and password. It says my password is incorrect, but I know its right as it works with my on prem account. Should these details not all get synced as part of the AD connect sync.

If I reset my password in Azure AD I can them login in and access the app successfully. Should I be able to access the app on a non domain joined device? Surely I shouldn't have to reset my password in Azure AD?

Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
13,443 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 21,881 Reputation points Microsoft Employee

    If you're using a Microsoft account and not an Azure AD account, you can run into this issue. Can you confirm that you are using an Azure AD created account when this happens?

    AD Connect prerequisites:

    An Azure AD Global Administrator account for the Azure AD directory you wish to integrate with. This must be a school or organization account and cannot be a Microsoft account.
    This list is starting to be quite long so I understand that it is easy to miss. As soon as I pick something up in these forums, I add it to the documentation.

    It is also possible that there is a connectivity issue or duplicate object.

    Also, check your conditional access policies to make sure there isn't something blocking unjoined devices.

    2 people found this answer helpful.
    No comments