Forum Discussion
Silently configure OneDrive using Windows 10 or domain credentials
The settings look good..
When i mentioned the OU,it was for people who are distributing the keys using a GPO..i am assuming you have manually made these keys on the test machine?
When you reboot and launch onedrive,what is the behavior?
Yes, I am setting registry manually.
After rebooting, ODB WIzard start, asking to enter credential (UPN).
Please advise.
Avian
- spgrinchAug 30, 2019Copper Contributor
Manuel_Martinez either should work whether it's a federated domain or managed. There are separate steps for federated vs managed, but the same process through azure ad connect hybrid setup wizard.
- Manuel_MartinezAug 01, 2019Copper Contributor
Does anybody know if we need an Azure AD Sync with an ADFS infrastructure or if Azure AD Sync with Password Sync will work as well?
- bKeskiMar 15, 2019Copper Contributor
in GPO explanation:
If you enable this setting, users who are signed in on the PC with the primary Windows account (the account used to join the PC to the domain) can set up the sync client without entering the credentials for the account. Users will still be shown One Drive Setup so they can select folders to sync and change the location of their One Drive folder.
So only admin, who have joined PC to domain can set up Onedrive silently???
- Admin PbibeNov 13, 2018Copper Contributor
Hello,
you need to run GPRESULT with admin rights. Launch a command prompt with administrator rights, and in the cmd window launch your GPRESULT command (including the option "/scope computer" if you only want to report on the GPO affecting the computer)
Michel
- Darren KattanJul 13, 2018Copper ContributorHave you found away around the users having to hit the login button? I am also stuck here.
- null nullApr 11, 2018Copper Contributor
I would like to know this too. We don't have ADFS, will this work without it?
- Oliver RoosMar 12, 2018Copper Contributor
Does anybody know if we need an Azure AD Sync with an ADFS infrastructure or if Azure AD Sync with Password Sync will work as well? I'm still not able to get this working ...
- Rudianto ZhuoMar 09, 2018Copper Contributor
Hi,
anyone have the idea why the GPO not applied on the registry?
I tried to run gpresult /H result.html and seems the gpo applied to the machine. but not applied in registry.
- Rogier DittnerFeb 28, 2018Copper Contributor
What i got sofar, SSO working
Got adsync running sso enabled for Office..
Computer\Policies\Administrative Templates\Onedrive
Allow syncing OneDrive accounts for only specific organizations
State
Enabled
Tenant GUID
<removed>
Enable OneDrive Files On-Demand
State
Enabled
Prevent OneDrive from generating network traffic until the user signs in to OneDrive
State
Enabled
Silently configure OneDrive using the primary Windows account
State
Enabled
The maximum size of a user's OneDrive for Business before they will be prompted to choose which folders are downloaded
State
Enabled
Tenant Path
<removed>
Value
50000
User\Policies\Administrative Templates\Onedrive
Coauthoring and in-app sharing for Office files
State
Enabled
Delay updating OneDrive.exe until the second release wave
State
Enabled
Prevent users from changing the location of their OneDrive folder
State
Enabled
Tenant Path
<removed>
Value
1
Prevent users from synchronizing personal OneDrive accounts
State
Enabled
Prevent users from using the remote file fetch feature to access files on the computer
State
Enabled
Set the default location for the OneDrive folder
State
Enabled
Tenant Path
<removed>
Value
%UserProfile%
Users can choose how to handle Office files in conflict
State
Enabled
Sts-adfs in trusted zone. EnableADAL off (0)
Configuration in ADFS
"/adfs/services/trust/13/windowstransport": Enabled
However this is only internal, external this is disabled
The users use a different UPN Suffix than the Domain Name.
The email address is populated, When I start Onedrive with:
"C:\Program Files\internet explorer\iexplore.exe" odopen://sync?useremail=<email>
The email address is not populated, When I start Onedrive with:
%LocalAppdata%\Microsoft\OneDrive\OneDrive.exe odopen://sync?useremail=<email>
However, still the users need to hit the Login button. Anyone stuck, feel free to duplicate my settings and try to fix the Login automation.
- Rogier DittnerFeb 28, 2018Copper Contributor
I'm on the exact same page you'r stuck at.
Our config:
ADFS internal, Netscaler as WAP external
Internal clients have recieve internal ADFS IP from DNS
STS is in trusted zone
I got the population working by starting:
"C:\Program Files\internet explorer\iexplore.exe" odopen://sync?useremail=<email>
because using %LocalAppdata%\Microsoft\OneDrive\OneDrive.exe odopen://sync?useremail=<email> does not populate
Still users are required to hit the login button.... that's where i'm stuck
- Oliver RoosFeb 27, 2018Copper Contributor
Does anybody know, what microsoft means with the primary Windows account in the setting "Silently configure OneDrive using the primary Windows account"?
The name of that setting was "Silently configure OneDrive using Windows 10 or domain credentials" - so do they still support using domain credentials?
I'm not able to get this setting working - we use Azure AD Connect to put our local domain users to Azure AD and Office365.
- Ted MurrayFeb 27, 2018Copper ContributorI have not been able to work on this yet. Will try to remember to post here when I do.
- Rogier DittnerFeb 27, 2018Copper Contributor
Anyone made some progress?
- Ted MurrayFeb 15, 2018Copper ContributorDarn. Was hoping my first post here would have been helpful. Sounds like I may run into the same issue when we finally have time to start testing this. If I manage to find a solution I'll share it. Hopefully Microsoft will get it working. Guessing that's why the feature is still labeled preview.
- Justin HollomanFeb 14, 2018Copper ContributorThanks for the suggestion, Ted. Unfortunately, we already have our corporate IPs exempted from MFA so that 2-factor is not required while inside a company office. Somehow, that doesn't seem to apply to the OneDrive silent config, though I can't understand how/why.
- Ted MurrayFeb 13, 2018Copper Contributor
Justin Holloman wrote:
Hi Avian,
I think I have confirmed that the silent config is not compatible with MFA. I was playing around with this all day and couldn't get it to work. Then I turned off MFA on my test account and just like that the silent config started working. Unfortunately, that means I won't be able to use this feature in my org, as MFA is a requirement. Hope this helps shed some light on your troubles.
Justin
Justin,Try whitelisting your work's public IP address in your MFA policy. That should allow the feature to work as MFA would essentially be off inside your network due to the whitelist. MFA would still be required when users log in while outside your network though.
I just started looking into the silent config feature myself so haven't even started testing it yet. However, we already have whitelisting for MFA setup and it works great. Instances where MFA can get in the way are no longer an issue, so long as the user or device is in the building.
Hope this helps.
- Avian 1Jan 30, 2018Iron Contributor
Thanks for clarification Justin.
I will wait once OneDrive Silent Aithentication start supporting MFA.
- Justin HollomanJan 29, 2018Copper ContributorHi Avian,
I think I have confirmed that the silent config is not compatible with MFA. I was playing around with this all day and couldn't get it to work. Then I turned off MFA on my test account and just like that the silent config started working. Unfortunately, that means I won't be able to use this feature in my org, as MFA is a requirement. Hope this helps shed some light on your troubles.
Justin - Tom PetersonJan 26, 2018Copper Contributor
We are using two group policies, one for computer, and one for user settings.
The User policy sets the "default location for the OneDrive folder," and includes the tenant GUID of our OneDrive. It also "prevents users from changing the location of their OneDrive folder" (which also includes the tenant GUID). This policy also contains a preference to set the EnableADAL registry value (DWORD:0x1) in HKCU\Software\Microsoft\OneDrive.
The Computer policy sets the "Silently configure OneDrive using the primary Windows account," sets the "Allow synching OneDrive Accounts for only specific organizations" (includes the tenant GUID), and also sets the "maximum size of a user's OneDrive" (and also includes the tenant GUID).
You should check the version of the OneDrive policy templates you are using to ensure they are also as recent as the OneDriveSetup.exe. Earlier versions did not incorporate the tenantGUID in the policy editor.
- Avian 1Jan 25, 2018Iron Contributor
Hi Tom
Just changes in the registry and copy the OnedriveSetup.exe in C:\Windows\SysWOW64 not working, I might be missing some steps.
Can you please share the steps to which you implement?
I am using latest client Build. 17.3.1076.1026.
Avian
- neal smithJan 25, 2018Copper ContributorThe first thing i tried was to use latest onedrivesetup, from Oct 2017, in my image build. Still no automation occured.
- Tom PetersonJan 25, 2018Copper Contributor
We were advised that the version of OneDriveSetup.exe must be at least 17.3.7073.1013 or later (10/26/2017) in order for the silent configuration to work. We have been upgrading the OneDriveSetup.exe in C:\Windows\SysWOW64 in order to force this to work, and it has. We are searching for more effective ways to include the updated setup in our image.
- neal smithDec 14, 2017Copper Contributor
After setting the ADAL registry key as noted in the original deployment article, and setting the silentaccountconfig reg key, I can ONLY get this to work if my domain users perform "Add a work or school account" first.
If I remove the work account from this domain computer, the silentconfig of onedrive is now broken, and useless.
The entire feature is actually useless if all users need to manually perform the "add work account" process. This process so far.... is not actually silent until we can truly simply use the domain credential, or if there is a way to automate the "add work account" process.
- Avian 1Nov 21, 2017Iron Contributor
Priyank
Whenever user enter his UPN on any office 365 site(OWA/SP/OneDrive), it redirects to siteminder to validate authentication and then validate and logged in automatically. I think here is the problem, after installing Onedrive, it is not automatically logging so probably not getting any endpoint.
I am attaching fiddler screenshot for your reference.
Can you please share the screenshot of your machine registry if possible? I want to compare with my registry,may be I am missing something
Let me know what else I need to check. - DeletedNov 21, 2017
Avian 1 I forgot the link sorry, https://www.fiddlerbook.com/fiddler/help/httpsdecryption.asp