Migrate from Federated to Password Hash for Office Pro Plus

%3CLINGO-SUB%20id%3D%22lingo-sub-936340%22%20slang%3D%22en-US%22%3EMigrate%20from%20Federated%20to%20Password%20Hash%20for%20Office%20Pro%20Plus%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-936340%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20in%20the%20process%20of%20changing%20our%20authentication%20method%20from%20ADFS%20to%20Password%20Hash%20Sync.%20This%20change%20obviously%20affects%20logins%20to%20Office%20365%20on%20the%20web.%20How%20does%20it%20affect%20Office%20365%20ProPlus%20clients%20who%20have%20already%20logged%20in%20and%20got%20licensed%3F%20We%20use%20Outlook%20and%20OneNote%20Class%20Notebook%20heavily%20and%20need%20to%20know%20if%20our%20student's%20notebooks%20will%20continue%20syncing%2C%20or%20will%20they%20have%20to%20enter%20their%20credentials%20again%20for%20licensing%20and%20permissions%20to%20the%20notebooks.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-936340%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EEducation%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOneNote%20Education%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EProPlus%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1413970%22%20slang%3D%22en-US%22%3ERe%3A%20Migrate%20from%20Federated%20to%20Password%20Hash%20for%20Office%20Pro%20Plus%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1413970%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F395259%22%20target%3D%22_blank%22%3E%40FishInDisguise%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20deploy%20Seamless%20Single%20sign-on%20as%20part%20of%20PHS%2C%20then%20it%20is%20more%20than%20likely%20that%20you%20will%20not%20see%20any%20problems%20with%20users%20being%20challenged%20for%20credentials%20once%20the%20switch%20has%20taken%20place.%20%26nbsp%3BHowever%2C%20this%20cannot%20be%20absolutely%20guaranteed%20i'm%20afraid.%20%26nbsp%3BThe%20behaviour%20of%20O365%20Pro%20Plus%20in%20these%20situations%20is%20almost%20impossible%20to%20completely%20predict.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDeploying%20the%20URL's%20for%20SSSO%20should%20help%20though.%20%26nbsp%3BYou%20can%20read%20more%20about%20this%20here%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-sso-quick-start%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-sso-quick-start%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20remember%20that%20your%20users%20O365%20Pro%20Plus%20clients%20will%20be%20at%20different%20stages%20of%20the%2030%20day%20call%20home%20to%20do%20a%20licence%20verification%20cycle.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEdit%2C%20just%20noticed%20this%20is%20a%20very%20old%20post%20so%20guessing%20you%20got%20this%20sorted%20out.%20%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Fhtml%2Fimages%2Femoticons%2Flaugh_40x40.gif%22%20alt%3D%22%3Alol%3A%22%20title%3D%22%3Alol%3A%22%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Regular Visitor

I am in the process of changing our authentication method from ADFS to Password Hash Sync. This change obviously affects logins to Office 365 on the web. How does it affect Office 365 ProPlus clients who have already logged in and got licensed? We use Outlook and OneNote Class Notebook heavily and need to know if our student's notebooks will continue syncing, or will they have to enter their credentials again for licensing and permissions to the notebooks.

1 Reply

@FishInDisguise 

 

If you deploy Seamless Single sign-on as part of PHS, then it is more than likely that you will not see any problems with users being challenged for credentials once the switch has taken place.  However, this cannot be absolutely guaranteed i'm afraid.  The behaviour of O365 Pro Plus in these situations is almost impossible to completely predict.

 

Deploying the URL's for SSSO should help though.  You can read more about this here - https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start

 

Just remember that your users O365 Pro Plus clients will be at different stages of the 30 day call home to do a licence verification cycle.

 

Edit, just noticed this is a very old post so guessing you got this sorted out.  :lol: