Forum Discussion
DivideByZero
Jun 10, 2024Copper Contributor
SSO issues in Word and Excel, but not Outlook
Hi, Strange issue started a month ago at a customer site. They use RDS with Office 365 installed. Historically this has been working fine, then it randomly stopped signing in properly for all use...
WelkasWorld
Jun 10, 2024Brass Contributor
Hi,
A lot of people are currently experiencing a similar issue with SSO.
It might be due to the fact that Microsoft is after changing the Windows Single sign on experience. In order to be compliant with the Digital Markets Act (DMA) within the European Economic Area (EEA), Microsoft has started altering how Windows operates to align with global regulations like the DMA. One significant change involves the sign-in process for apps on Windows.
If you look at the sign-in logs for the users and see error code 9002341 or similar with the failure reason being "User is required to permit SSO", have a read through my blog post below.
https://www.welkasworld.com/post/tackling-mfa-fatigue-a-solution-for-sign-in-error-code-9002341-user-is-required-to-permit-sso
Hopefully this helps.
A lot of people are currently experiencing a similar issue with SSO.
It might be due to the fact that Microsoft is after changing the Windows Single sign on experience. In order to be compliant with the Digital Markets Act (DMA) within the European Economic Area (EEA), Microsoft has started altering how Windows operates to align with global regulations like the DMA. One significant change involves the sign-in process for apps on Windows.
If you look at the sign-in logs for the users and see error code 9002341 or similar with the failure reason being "User is required to permit SSO", have a read through my blog post below.
https://www.welkasworld.com/post/tackling-mfa-fatigue-a-solution-for-sign-in-error-code-9002341-user-is-required-to-permit-sso
Hopefully this helps.
- DivideByZeroJun 11, 2024Copper ContributorThat sounded really hopeful, but sadly it's not that. I don't see any failures in the sign in logs for the Office sign ins.
What is weird is that SSO does work if you launch Outlook twice. Yet it will never automatically work if you launch Word or Excel as many times as you like.
It definitely feels like something is happening with Office itself all of a sudden, or maybe Windows Server... but if that was the case I would expect this to impact more people and see more posts about this. Having done a "in the last month" search for this, very few hits.- DivideByZeroJun 11, 2024Copper ContributorActually, slight amendment to that. SSO works normally from Outlook, it's just the license took 2 logins to pull down until we started saving the \appdata\local\microsoft\office folder.
However, on a new login you can do the following.
1) Start word, get prompted to sign in via pop up.
2) cancel and close Word.
3) Start word, get prompted to sign in via pop up.
4) cancel and close Word.
5) Start word, get prompted to sign in via pop up.
6) cancel and close Word.
7) You can do this all day...
😎 START OUTLOOK. A sign in window pops up and does something automatically and signs you in. (proper seamless SSO).
9) Start Word, it's signed in.
So, SSO is working in Outlook, but not Word or Excel.
SSO also works as expected to share sharepoint.com - login happens seamlessly, nothing to type in etc.
It's just Word and Excel that it doesn't work for.- WelkasWorldJun 11, 2024Brass ContributorSorry my suggestion didn't work. That's a really strange issue your customer is experiencing.
It's either something to do with licensing or perhaps a Windows update if it's all been working fine up until about a month ago.
I would probably try to delete Office365 credentials saved in the credential manager if that's not too much of a hassle, then try and sign into Outlook, once signed in, within the Outlook app go File> Office Account > update license, then restart the app and try and open up Word and Excel afterwards and see if they still go into an authentication loop.
I did hear about Word and Excel issues (not necessarily authentication related) when some of our customers assigned Copilot licenses for example.
Do any of the logs (Entra ID + Event viewer etc.) show any errors/ interrupted sign ins at all?