Forum Discussion
JayO78
Dec 21, 2022Copper Contributor
Office 365 Shared Computer Activation Prompts for user to sign in when SSO is enabled
Setting up a shared machine to be used by multiple people. Following items have been set up. * GPO policy set " Use Shared computer activation" Enabled " specified selected PCs" * Office Version...
RNalivaika
Dec 22, 2022Iron Contributor
computer has to be aad joined or hybrid aad joined for sso to work. also, logging on to windows does not require second factor, so starting ms365app would require a first sign in with mfa.
to avoid authentication prompt, you could consider conditional access to not require mfa on compliant device (or IP, or other condition), but that would be added security risk ofc.
to avoid authentication prompt, you could consider conditional access to not require mfa on compliant device (or IP, or other condition), but that would be added security risk ofc.
- JayO78Dec 22, 2022Copper ContributorMachine is set up in a Hybrid [ Azure AD ] and is domain joined. This only appears to be happening with users who have MFA enabled on their account. SSO is acting like it can't validate the windows credentials and doesn't automatically prompt for the Approved Sign in. Tested a few users who do not have MFA set up and it is working as expected. Account gets verified and a license is acquired.