Updates to auto sign in with on-prem Active Directory accounts

%3CLINGO-SUB%20id%3D%22lingo-sub-1185301%22%20slang%3D%22en-US%22%3EUpdates%20to%20auto%20sign%20in%20with%20on-prem%20Active%20Directory%20accounts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1185301%22%20slang%3D%22en-US%22%3E%3CDIV%3E%0A%3CP%3E%3CFONT%20size%3D%222%22%20color%3D%22%23000000%22%3E%3CSPAN%3EWe've%20heard%20your%20feedback%20and%20are%20committed%20to%20making%20your%20identity%20experience%20great.%20In%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3EEdge%20Beta%26nbsp%3B81.0.416.11%20and%20version%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E82.0.427.0%20onwards%2C%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3EOn-prem%20Active%20Directory%20account%20auto%20sign%20in%20(sign%20in%20with%20accounts%20of%20the%20type%20DOMAIN%5Cusername)%20will%20only%20be%20targeted%20to%20organizations%20that%20enable%20it.%26nbsp%3B%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20size%3D%222%22%20color%3D%22%23000000%22%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20size%3D%222%22%20color%3D%22%23000000%22%3E%3CSPAN%3EIf%20an%20organization%20does%20not%20turn%20this%20feature%20on%2C%20users%20will%20only%20be%20auto%20signed%20in%20with%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Ethe%20primary%20account%20on%20their%20operating%20system%20if%20it%20is%20an%20MSA%20or%20an%20AAD%20account.%20If%20there%20is%20no%20primary%20account%20or%20the%20primary%20account%20is%20an%20on-prem%20Active%20Directory%20account%2C%20users%20will%20not%20be%20signed%20into%20Microsoft%20Edge.%26nbsp%3BUsers%20that%20were%20auto%20signed%20in%20with%20their%20on-prem%20Active%20Directory%20accounts%20in%20a%20previous%20release%20will%20be%20able%20to%20sign%20out%20of%20it%20when%20they%20upgrade%26nbsp%3Bto%20newer%20versions%20of%20Microsoft%20Edge.%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3CDIV%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3CDIV%3E%0A%3CP%3E%3CFONT%20size%3D%222%22%20color%3D%22%23000000%22%3E%3CSPAN%3EIf%20you%20are%20an%20admin%20and%20you%20would%20like%20your%20users%20to%20be%20auto%20signed%20in%20with%20their%20on-prem%20Active%20Directory%20accounts%2C%20you%20can%20use%26nbsp%3Bthe%20ConfigureOnPremisesAccountAutoSignIn%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-US%2FDeployEdge%2Fmicrosoft-edge-policies%23configureonpremisesaccountautosignin%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-US%2FDeployEdge%2Fmicrosoft-edge-policies%23configureonpremisesaccountautosignin%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%3E)%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Epolicy%20to%20enable%20this.%20If%20you'd%20like%20to%20have%20your%20users%20auto%20signed%20in%20with%20their%20AAD%20accounts%20instead%2C%20please%20hybrid%20join%20your%20environment%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-federated-domains%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-federated-domains%3C%2FA%3E).%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3CDIV%3E%0A%3CP%3E%3CFONT%20size%3D%222%22%20color%3D%22%23000000%22%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3CDIV%3E%0A%3CP%3E%3CFONT%20size%3D%222%22%20color%3D%22%23000000%22%3E%3CSPAN%3EWe%20hope%20that%20this%20helps%20make%20your%20Identity%20experience%20in%20Microsoft%20Edge%20better.%20Let%20us%20know%20if%20there%20is%20anything%20we%20could%20do%20to%20make%20this%20experience%20better.%20Thanks!%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1258870%22%20slang%3D%22en-US%22%3ERe%3A%20Updates%20to%20auto%20sign%20in%20with%20on-prem%20Active%20Directory%20accounts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1258870%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F211254%22%20target%3D%22_blank%22%3E%40Avi%20Vaid%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Avi%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20you%20able%20to%20clarify%20a%20couple%20of%20points%20for%20me%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20on-premise%20AD%2C%20Azure%20AD%20Connect%20syncing%20users%20to%20Office%20365%2C%20with%20all%20services%20cloud-hosted.%20I%20thought%20I%20might%20be%20able%20to%20get%20automatic%20sign-in%20to%20each%20user's%20Office%20365%20identity%20in%20the%20same%20way%20Office%20apps%20do%20but%20from%20reading%20your%20post%20it%20sounds%20like%20this%20isn't%20possible%20(yet%3F)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20(I%20hope%20this%20doesn't%20sound%20facetious.)%20What%20is%20the%20benefit%20of%20having%20the%20user%20sign%20into%20Edge%20with%20the%20on-premise%20AD%20account%2C%20if%20not%20to%20sync%20with%20the%20associated%20AzureAD%2FOffice365%20identity%3F%20Does%20it%20just%20improve%20authentication%20with%20on-premise%20services%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20If%20we%20hybrid-join%20our%20domain%20PCs%2C%20will%20users%20that%20login%20in%20the%20standard%20way%20(DOMAIN%5CUsername)%20then%20be%20signed%20in%20with%20their%20AzureAD%2FOffice365%20identity%20automatically%3F%20Or%20do%20they%20then%20need%20to%20start%20logging%20in%20using%20their%20e-mail%20address%20or%20similar%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers!%3CBR%20%2F%3EChris%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1266207%22%20slang%3D%22en-US%22%3ERe%3A%20Updates%20to%20auto%20sign%20in%20with%20on-prem%20Active%20Directory%20accounts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1266207%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F296037%22%20target%3D%22_blank%22%3E%40sheffieldc%3C%2FA%3E%26nbsp%3BChris%2C%20great%20questions.%20As%20of%20now%20we%20don't%20have%20a%20way%20to%20get%20auto%20sign%20in%20with%20the%20O365%20account%20without%20hybrid%20joining.%20Some%20thoughts%20on%20your%20questions%20below%3A%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EThe%20benefits%20are%20having%20a%20specified%20work%20profile%2C%20this%20helps%20with%20windows%20information%20protection%20features.%20It%20will%20also%20come%20into%20play%20in%20the%20future%20when%20we%20enable%20on-premise%20sync%20and%20if%20we%20create%20preferred%20SSO%20with%20the%20signed%20in%20account%3C%2FLI%3E%0A%3CLI%3EYes.%20If%20you%20hybrid%20join%20your%20domain%20PC%2C%20users%20can%20log%20into%20windows%20as%20DOMAIN%5CUsername%20and%20then%20be%20signed%20into%20Edge%20with%20their%20AAD%20(O365)%20accounts%20automatically.%3C%2FLI%3E%0A%3C%2FOL%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1266925%22%20slang%3D%22en-US%22%3ERe%3A%20Updates%20to%20auto%20sign%20in%20with%20on-prem%20Active%20Directory%20accounts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1266925%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F211254%22%20target%3D%22_blank%22%3E%40Avi%20Vaid%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat's%20great%2C%20thanks%20Avi!%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Microsoft

We've heard your feedback and are committed to making your identity experience great. In Edge Beta 81.0.416.11 and version 82.0.427.0 onwards, On-prem Active Directory account auto sign in (sign in with accounts of the type DOMAIN\username) will only be targeted to organizations that enable it. 

 

If an organization does not turn this feature on, users will only be auto signed in with the primary account on their operating system if it is an MSA or an AAD account. If there is no primary account or the primary account is an on-prem Active Directory account, users will not be signed into Microsoft Edge. Users that were auto signed in with their on-prem Active Directory accounts in a previous release will be able to sign out of it when they upgrade to newer versions of Microsoft Edge.

 

If you are an admin and you would like your users to be auto signed in with their on-prem Active Directory accounts, you can use the ConfigureOnPremisesAccountAutoSignIn (https://docs.microsoft.com/en-US/DeployEdge/microsoft-edge-policies#configureonpremisesaccountautosi...) policy to enable this. If you'd like to have your users auto signed in with their AAD accounts instead, please hybrid join your environment (https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-federated-domain...).

 

We hope that this helps make your Identity experience in Microsoft Edge better. Let us know if there is anything we could do to make this experience better. Thanks!

3 Replies
Highlighted

@Avi Vaid

 

Hi Avi

 

Are you able to clarify a couple of points for me?

 

We have on-premise AD, Azure AD Connect syncing users to Office 365, with all services cloud-hosted. I thought I might be able to get automatic sign-in to each user's Office 365 identity in the same way Office apps do but from reading your post it sounds like this isn't possible (yet?)

 

1. (I hope this doesn't sound facetious.) What is the benefit of having the user sign into Edge with the on-premise AD account, if not to sync with the associated AzureAD/Office365 identity? Does it just improve authentication with on-premise services?

 

2. If we hybrid-join our domain PCs, will users that login in the standard way (DOMAIN\Username) then be signed in with their AzureAD/Office365 identity automatically? Or do they then need to start logging in using their e-mail address or similar?

 

Cheers!
Chris

Highlighted

@sheffieldc Chris, great questions. As of now we don't have a way to get auto sign in with the O365 account without hybrid joining. Some thoughts on your questions below:

  1. The benefits are having a specified work profile, this helps with windows information protection features. It will also come into play in the future when we enable on-premise sync and if we create preferred SSO with the signed in account
  2. Yes. If you hybrid join your domain PC, users can log into windows as DOMAIN\Username and then be signed into Edge with their AAD (O365) accounts automatically.
Highlighted

@Avi Vaid

 

That's great, thanks Avi!