SOLVED

Can some apps use ADFS and some Azure AD?

%3CLINGO-SUB%20id%3D%22lingo-sub-401480%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20some%20apps%20use%20ADFS%20and%20some%20Azure%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-401480%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20for%20clarification%20on%20what%20you%20said%2C%20you%20%3CSTRONG%3ECAN'T%26nbsp%3B%3C%2FSTRONG%3Ehave%20sharepoint%20use%20ADFS%20and%20exchange%20use%20PHS.....BUT%20you%26nbsp%3B%3CSTRONG%3ECAN%26nbsp%3B%3C%2FSTRONG%3Ehave%20all%20of%20office%20use%20ADFS%20and%20Salesforce%20use%20PHS%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-382665%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20some%20apps%20use%20ADFS%20and%20some%20Azure%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-382665%22%20slang%3D%22en-US%22%3EThat%20makes%20sense.%20Thanks!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-382475%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20some%20apps%20use%20ADFS%20and%20some%20Azure%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-382475%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can.%20What%20you%20cannot%20do%20is%20have%20some%20of%20the%20applications%20within%20the%20Office%20365%20suite%20use%20AD%20FS%2C%20while%20others%20use%20other%20auth%20methods.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-408330%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20some%20apps%20use%20ADFS%20and%20some%20Azure%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-408330%22%20slang%3D%22en-US%22%3E%3CP%3EYup%2C%20as%20long%20as%20the%20corresponding%20application%20allows%20you%20do%20configure%20an%20authentication%20method%20separate%20from%20the%20%22general%22%20Azure%20AD%20one.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-380537%22%20slang%3D%22en-US%22%3ECan%20some%20apps%20use%20ADFS%20and%20some%20Azure%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-380537%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20use%20ADFS%20for%20around%2010%20apps%20for%20SSO%20including%20Office%20365.%26nbsp%3B%20We%20also%20have%20password%20hash%20sync%20enabled%20in%20Azure%20AD%20Connect%20as%20a%20backup.%26nbsp%3B%20%26nbsp%3BI%20would%20like%20to%20start%20testing%20Azure%20AD%20for%20SSO%20in%20hopes%20that%20we%20can%20retire%20ADFS%20someday.%20I%20would%20like%20to%20start%20testing%20azure%20app%20market%20apps%20as%20well%20as%20saml%20based%20apps.%26nbsp%3B%20I%20was%20thinking%20about%20getting%20my%20Docusign%20test%20environment%20connected%20with%20our%20Azure%20AD%20instead%20of%20ADFS%2C%20but%20I%20don't%20want%20to%20break%20prod%20if%20what%20I%20am%20envisioning%20is%20not%20supported%20or%20does%20not%20work.%26nbsp%3B%20%26nbsp%3BThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-380537%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2283097%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20some%20apps%20use%20ADFS%20and%20some%20Azure%20AD%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2283097%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BCan%20you%20elaborate%20on%20this%20a%20bit%3F%20I%20am%20having%20issues%20getting%20a%20user%20to%20authenticate%20against%20Azure%20AD.%26nbsp%3B%20My%20application%20keeps%20pointing%20me%20back%20at%20ADFS%20even%20though%20the%20SAML%20connection%20is%20setup%20directly%20to%20Azure%20AD%20as%20a%20custom%20enterprise%20app%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

We use ADFS for around 10 apps for SSO including Office 365.  We also have password hash sync enabled in Azure AD Connect as a backup.   I would like to start testing Azure AD for SSO in hopes that we can retire ADFS someday. I would like to start testing azure app market apps as well as saml based apps.  I was thinking about getting my Docusign test environment connected with our Azure AD instead of ADFS, but I don't want to break prod if what I am envisioning is not supported or does not work.   Thanks

5 Replies
best response confirmed by brentmattson (Occasional Contributor)
Solution

You can. What you cannot do is have some of the applications within the Office 365 suite use AD FS, while others use other auth methods. 

That makes sense. Thanks!

Just for clarification on what you said, you CAN'T have sharepoint use ADFS and exchange use PHS.....BUT you CAN have all of office use ADFS and Salesforce use PHS?

 

 

Thanks

Yup, as long as the corresponding application allows you do configure an authentication method separate from the "general" Azure AD one.

@Vasil Michev Can you elaborate on this a bit? I am having issues getting a user to authenticate against Azure AD.  My application keeps pointing me back at ADFS even though the SAML connection is setup directly to Azure AD as a custom enterprise app