Forum Discussion

Tom Murray's avatar
Tom Murray
Copper Contributor
Aug 15, 2017

Azure AD W10 and Outlook

Hi All,

We have Azure AD joined machines, coniditional access and with Windows hello enabled, all our applications work with AAD Proxy single signon.

 

Currently outlook (office365) is our biggest problems, when you launch outlook for the first time (and also if your password changes) it prompts for the Windows Hello pin, then errors becasue it needs the password, ou have to click other users then enter O365 username and password.

 

Does anyone use Azure AD machines + Windows Hello without and Outlook credentials issues?

 

Should Windows hello be able to authenticate users in Outlook and am I missing something?

or

Is there a way to get outlook to default username and password prompt with windows hello enabled on the OS?

 

Thanks,

17 Replies

  • Caleb McGary's avatar
    Caleb McGary
    Copper Contributor

    I'm also experiencing this issue; I'm being prompted for azuread\username@domain.com after opening outlook; any solutions?

     

     

    • Lane HOY's avatar
      Lane HOY
      Copper Contributor

      I am experiencing the same issue, really having a hard time as the popup to logon comes back every few minutes and even removing azuread/ does not allow successful logon...

  • We are experiencing the same problem in one of our tenants. We have a similar setup as described in a couple of the posts here.

     

    We are currently working with Microsoft support on the issue. Will keep you updated on the progress. 

  • Hi Tom,

     

    Do you have Modern Authentication enabled in Exchange Online for your tenant? Also, are you running the Click 2 Run version of Office?

    • Tom Murray's avatar
      Tom Murray
      Copper Contributor

      Hi Grant,

       

      Yes to both, we use the click to run version of office, and Modern Authentication is enabled.

       

      Name                                       OAuth2ClientProfileEnabled

      ----                                       --------------------------

      *************.onmicrosoft.com                       True

       

      • Deleted's avatar
        Deleted

        Tom,

         

        I was able to reproduce your issue in my environment. It looks like if you signed into Windows using your Hello PIN instead of your password, it traps you in the authentication pop-up cycle. I believe you can click the "more choices" link at the bottom of the prompt and use the standard email address and password, but I imagine most end-users won't know to do that. Microsoft needs to either update Outlook 2016 so that it can properly utilize Windows Hello, or make it smart enough to stop asking users for a PIN that won't work.

Resources