Forum Widgets
Latest Discussions
Authenticator App for visionOS Apple Vision Pro
Please add more options to visionOS version. I want to sign in with my personal account and synchronize my TOTP tokens and passwords into the visionOS so that I do not have to open my phone while wearing the headset (huge pain since the iphone app requires face unlock which does NOT work when wearing the headset). Also please support retina unlock in the visionOS app. Also support authenticator request approvals from inside the visionOS app.whatisinanameFeb 03, 2025Copper Contributor28Views1like0CommentsFederation Issues - No protocol handlers?
Hi All, It's been a number of years since I've federated a domain with Entra, i'm flipping this back in a home environment to complete some testing. Would appreciate some troubleshooting thoughts. What from memory was a quick task, I've spent waaaaay to long on this today. I've rebuilt the environment a number of times with the same outcome. Install ADFS (Enabled the sign-in page). Install WAP. Generate Let's Encrypt certificate and provide to the servers. Port Forward 443 to the WAP server. Use Entra Connect to Federate the domain (AD FS Config looks good and generated as Microsoft Office 365 Identity Platform) WAP is configured via AAD Connect (Blank but seems alright talking back to ADFS) I can hit https://adfs.domain.com/adfs/ls/idpinitiatedsignon.aspx and authenticate with UPN internally/externally. I can hit https://adfs.domain.com/FederationMetadata/2007-06/FederationMetadata.xml internally/externally. I also setup IAMShowcase to test (SAML 2.0 Test Service Provider) and published the app via the WAP, worked fine for SP and IDP initiated flows. Interestingly enough, I am chucked the following error from the ADFS redirection with M365 authentication: Error details: MSIS7065: There are no registered protocol handlers on path /adfs/ls/ to process the incoming request. This raises an error on the ADFS server ID#364, I've rebuilt a few times and havent been able to find much in troubleshooting. Would love to hear if someone else has seen something similar, i'm at a bit of a loss here. Encountered error during federation passive request. Additional Data Protocol Name: Relying Party: Exception details: Microsoft.IdentityServer.Web.IdPInitiatedSignonPageDisabledException: MSIS7012: An error occurred while processing the request. Contact your administrator for details. at Microsoft.IdentityServer.Web.Protocols.Saml.IdpInitiatedSignOnRequestSerializer.ReadMessage(WrappedHttpListenerRequest httpRequest) at Microsoft.IdentityServer.Web.Protocols.Saml.HttpSamlMessageFactory.CreateMessage(WrappedHttpListenerRequest httpRequest) at Microsoft.IdentityServer.Web.Protocols.Saml.SamlContextFactory.CreateProtocolContextFromRequest(WrappedHttpListenerRequest request, ProtocolContext& protocolContext) at Microsoft.IdentityServer.Web.Protocols.Saml.SamlProtocolHandler.CreateProtocolContext(WrappedHttpListenerRequest request) at Microsoft.IdentityServer.Web.PassiveProtocolListener.GetProtocolHandler(WrappedHttpListenerRequest request, ProtocolContext& protocolContext, PassiveProtocolHandler& protocolHandler) at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context) Get-MgFederatedDomainFederationConfiguration -Identity Domain.com ActiveSignInUri : https://adfs.domain/adfs/services/trust/2005/usernamemixed IssuerUri : http://domain/adfs/services/trust/ MetadataExchangeUri : https://adfs.domain/adfs/services/trust/mex PassiveSignInUri : https://adfs.domain/adfs/ls/ PreferredAuthenticationProtocol : wsFed SignOutUri : https://adfs.domain/adfs/ls/SolvedMiikeJan 31, 2025Brass Contributor510Views1like15CommentsProvide accounts for Microsoft Authenticator centrally
In our IT department, we manage our mobile devices with Microsoft Intune. We have a group of maintenance employees who need access to production machines on the shopfloor using mobile devices. The access to these machines are static users or OTP-based access. Now I would like to provide all maintenance employees and their mobile devices with the Microsoft Authenticator and provide all accesses for these machines as preconfigured accounts. Is this possible with Intune or another option? I don't want to make the Microsoft Authenticator app available to the maintenance staff (we've already managed that), but rather defined accounts for all Microsoft Authenticator clients.Bordon0116Jan 23, 2025Copper Contributor29Views1like1CommentAuthenticator app issue
I am trying to log into Outlook and Teams on my iphone. When I try to enter in Username & PW, I get forced to open authenticator app, which asks for the same log in details I try to enter into Teams and Outlook, then it asks me to enter an authenticator app code which I cannot access as the current window prevents it from opening. I go back and have to start the whole process again. I just seem to go around in circles and end up in the same spot. i am the admin for the account , so i am unable to reset anything.nagacvJan 19, 2025Copper Contributor176Views0likes2CommentsCA policy for corporate devices
I would like to create a conditional access policy to block all non corporate devices from accessing Office 365 resources. I created a policy: Applies to -> User Group Applies to -> all resources Applies to -> Win 10 Filter for devices exception-> Ownership: company & trust type: Entra Hybrid joined. Action: block The above works fine for office desktop login, i.e. blocks non corporate devices and allows corporate devices. However, a side effect is that sign ins from browser on a corporate device is still blocked.AhmedSHMKJan 17, 2025Brass Contributor65Views1like7CommentsAuthentication Methods - FIDO2 & Authenticator Not Working Together
The issue is that my users are having trouble using the Microsoft Authenticator for authentication specificallly after they are being added to the FIDO2 authentication method. Before that, Authenticator works fine. But after being added to FIDO2, when they try to sign in, the "Authenticator" option is no longer visible. The only option is with the security key (and passkey). {And when I remove a user from FIDO2, the Authenticator option comes back.} Is there a way during sign in to offer both options to users?SolvedMario_MorelJan 16, 2025Copper Contributor2.1KViews0likes9CommentsMicrosoft Authenticator Passkeys for Entra ID on unmanaged devices
Hello, has anyone successfully registered passkeys on an unmanaged phone in an organisation with device compliance policies? Use case is to provide a phishing-resistant MFA option via Authenticator app for logging into apps on their desktop. Users already have authenticator app on their phone and do number matching MFA. https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-register-passkey-authenticator?tabs=iOS When I select "Create a passkey" - I need to log into my account. However I'm blocked from successful authentication because I have conditional access policies to require compliant devices. As my mobile phone is not enrolled into Intune, I never get to the step where the passkey is created and registered. Based on the constraints - it seems like passkeys cannot be used for unmanaged/BYOD devices for organisations that have device compliance policies. It can only be used for users who have enrolled their mobile phone. Looking to see if anyone has tips or different experience using passkeys on unmanaged mobile phones to log into Entra?63Views0likes0CommentsAzure MFA "Activation Failed" error with Microsoft Authenticator App
We've opened a premier ticket, but has anyone in the community seen this error before? We've got a few users that can't set up the Microsoft Authenticator app, and nothing we do is working. This is rolling out to all of our users overnight tonight, and none of our global testing has run into anything like this.Brent EllisJan 03, 2025Silver Contributor129KViews0likes16Commentsfailed set-up of a passkey for a personal MS account
After scanning the QR code (on the PC screen) in the Authenticator app on the Iphone, the error message “Error adding the passkey - Microsoft Authenticator does not support this passkey” (translated from German) appears. What does this mean ? How to prevent? Any help is appreciated.RegerDec 29, 2024Copper Contributor427Views1like2CommentsWhat are the FQDNs used for Office 365 logon and authentication?
Hello, We run a computer lab with Office 365 installed, with a network firewall that restricts all outbound internet traffic. We had made allowances for Office 365 logons so that users could use the Office 365 desktop applications, by allowing the following entries: *.office.com *.office365.com *.microsoftonline.com *.office.net And that was working until earlier this month. Suddenly a couple weeks ago, users were no longer able to sign into Office 365. I found this list here of all URLs and IPs that Microsoft tries to use for Office 365, and I tried adding *.auth.microsoft.com *.msftidentity.com *.msidentity.com to our firewall, but still no ability to log in. As a test, I disabled the outbound network block on one of the lab machines, and confirmed that I was indeed able to log in. So I know the issue is with this firewall rule. But I cannot add every single URL on that huge list above, that's not feasible. So please, I would like to know just what URLs are required for the Office 365 sign-on to work. I don't need or care about the other services on that list.md5hashDec 24, 2024Copper Contributor13KViews0likes7Comments
Resources
Tags
- Authentication324 Topics
- office 365213 Topics
- security151 Topics
- admin61 Topics
- Identity54 Topics
- multi-factor authentication45 Topics
- exchange42 Topics
- Azure AD40 Topics
- Microsoft 365 Apps36 Topics
- hybrid35 Topics