SSO to Google from Office 365 - different domains

%3CLINGO-SUB%20id%3D%22lingo-sub-2758208%22%20slang%3D%22en-US%22%3ESSO%20to%20Google%20from%20Office%20365%20-%20different%20domains%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2758208%22%20slang%3D%22en-US%22%3E%3CP%3ECurrently%20we%20have%20(contoso.com)%20as%20our%20domain%20for%20office%20365%20that%20is%20running%20adconnect%20on%20our%20on%20prem%20with%20hybrid%20aad.%20Identities%20are%20synced%20from%20on%20prem%20to%20o365%2C%20phs%2C%20and%20password%20write%20back.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20Gsuite%20on%20a%20different%20domain%20(westcontoso.org).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20it%20possible%20to%20set%20up%20sso%20from%20office%20365%20to%20gsuite%20so%20our%20users%20can%20use%20their%20o365%20credentials%20to%20log%20in%20to%20chromebooks%20and%20android%20phones%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOne%20more%20question%2C%20what%20would%20be%20the%20best%20way%20to%20test%20this%20with%20a%20gsuite%20in%20production%20without%20breaking%20anything%20%3F%20The%20g%20suite%20identity%20is%20mainly%20used%20for%20accessing%20chromebooks%20and%20managing%20android%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2758208%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2763267%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20to%20Google%20from%20Office%20365%20-%20different%20domains%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2763267%22%20slang%3D%22en-US%22%3EHi%20KleoNunket%2C%3CBR%20%2F%3E%3CBR%20%2F%3EIt%20should%20be%20possible%2C%20see%20the%20following%20link%20for%20more%20info%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fsaas-apps%2Fgoogle-apps-tutorial%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fsaas-apps%2Fgoogle-apps-tutorial%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20it%20solves%20your%20problem.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2767292%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20to%20Google%20from%20Office%20365%20-%20different%20domains%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2767292%22%20slang%3D%22en-US%22%3EHi%20HarriJaakkonen%2C%3CBR%20%2F%3E%3CBR%20%2F%3EIt%20looks%20that%20if%20i%20do%20this%20in%20production%20environment%2C%20my%20users%20won't%20be%20able%20to%20sign%20in%20with%20their%20g%20suite%20credentials%20as%20only%20one%20IDP%20can%20be%20used%20at%20a%20time%2C%20is%20this%20correct%20%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you.%3C%2FLINGO-BODY%3E
Occasional Contributor

Currently we have (contoso.com) as our domain for office 365 that is running adconnect on our on prem with hybrid aad. Identities are synced from on prem to o365, phs, and password write back.

 

We have Gsuite on a different domain (westcontoso.org).

 

Is it possible to set up sso from office 365 to gsuite so our users can use their o365 credentials to log in to chromebooks and android phones ?

 

One more question, what would be the best way to test this with a gsuite in production without breaking anything ? The g suite identity is mainly used for accessing chromebooks and managing android devices.

 

Thank you.

4 Replies
Hi KleoNunket,

It should be possible, see the following link for more info https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial

Hope it solves your problem.
Hi HarriJaakkonen,

It looks that if i do this in production environment, my users won't be able to sign in with their g suite credentials as only one IDP can be used at a time, is this correct ?

Thank you.
Yes, your users won't be temporarily able to sign-in but once the connector is up and running it should be finding them with their email address which is provided during the federation.

From the Microsoft documentation Q&A number 6:

Q: What should I do when I get an "invalid email" error message?

A: For this setup, the email attribute is required for the users to be able to sign-in. This attribute cannot be set manually.

The email attribute is auto populated for any user with a valid Exchange license. If user is not email-enabled, this error will be received as the application needs to get this attribute to give access.

You can go to portal.office.com with an Admin account, then click in the Admin center, billing, subscriptions, select your Microsoft 365 Subscription and then click on assign to users, select the users you want to check their subscription and in the right pane, click on edit licenses.

Once the Microsoft 365 license is assigned, it may take some minutes to be applied. After that, the user.mail attribute will be auto populated and the issue should be resolved.

Hope this one helps.
So, that means all my users would have to re enroll with their o365 credentials ?

I use gsuite to manage my users mobile devices. I would like to achieve the following, for example user john has a chromebook and an android phone.

I would like that user to have two accounts for a user:

A) john@gsuite.com account - with sso enabled so they can log in to chromebook with their o365 credentials.
B) johnmobile@gsuite.com account - no sso enabled, the password for this would be known by IT only, so we can manage and enroll their their mobile devices without resetting their o365 password.

I think G suite now offers ability to exclude OU or groups from SSO.

Thank you!