Forum Discussion
Azure AD W10 and Outlook
Hi All,
We have Azure AD joined machines, coniditional access and with Windows hello enabled, all our applications work with AAD Proxy single signon.
Currently outlook (office365) is our biggest problems, when you launch outlook for the first time (and also if your password changes) it prompts for the Windows Hello pin, then errors becasue it needs the password, ou have to click other users then enter O365 username and password.
Does anyone use Azure AD machines + Windows Hello without and Outlook credentials issues?
Should Windows hello be able to authenticate users in Outlook and am I missing something?
or
Is there a way to get outlook to default username and password prompt with windows hello enabled on the OS?
Thanks,
17 Replies
- Caleb McGaryCopper Contributor
I'm also experiencing this issue; I'm being prompted for azuread\username@domain.com after opening outlook; any solutions?
- Morten ReinhardtsenCopper Contributor
We are experiencing the same problem in one of our tenants. We have a similar setup as described in a couple of the posts here.
We are currently working with Microsoft support on the issue. Will keep you updated on the progress.
- Deleted
Hi Tom,
Do you have Modern Authentication enabled in Exchange Online for your tenant? Also, are you running the Click 2 Run version of Office?
- Tom MurrayCopper Contributor
Hi Grant,
Yes to both, we use the click to run version of office, and Modern Authentication is enabled.
Name OAuth2ClientProfileEnabled
---- --------------------------
*************.onmicrosoft.com True
- Deleted
Tom,
I was able to reproduce your issue in my environment. It looks like if you signed into Windows using your Hello PIN instead of your password, it traps you in the authentication pop-up cycle. I believe you can click the "more choices" link at the bottom of the prompt and use the standard email address and password, but I imagine most end-users won't know to do that. Microsoft needs to either update Outlook 2016 so that it can properly utilize Windows Hello, or make it smart enough to stop asking users for a PIN that won't work.