Home

Plan to Test ADFS SSO with Production O365 and to enable Federation in Production Azure Portal

%3CLINGO-SUB%20id%3D%22lingo-sub-175468%22%20slang%3D%22en-US%22%3EPlan%20to%20Test%20ADFS%20SSO%20with%20Production%20O365%20and%20to%20enable%20Federation%20in%20Production%20Azure%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-175468%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Team%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20have%20setup%20ADFS%20SSO%20for%20on-premises%20and%20integrated%20it%20with%20Azure%20Traffic%20Manager.%3C%2FP%3E%0A%3CP%3ENow%20i%20need%20to%20use%20ADFS%20SSO%20with%20O365%20Portal%2C%20it%20means%20i%20need%20to%20enable%20federated%20identity.%3C%2FP%3E%0A%3CP%3EAzure%20AD%20Connect%20is%20already%20enabled%20and%20sync%20is%20working%20for%20a%20domain%20in%20Azure%20Portal.%3C%2FP%3E%0A%3CP%3ERisk%20Factor%20is%20O365%20Portal%20is%20in%20Production%20use%20and%20on-premises%20AD%20is%20already%20in%20sync.%3C%2FP%3E%0A%3CP%3ECan%20you%20please%20advise%20how%20i%20Plan%20to%20Test%20ADFS%20SSO%20with%20Production%20Office%20365%3F%3C%2FP%3E%0A%3CP%3EShould%20i%20add%20a%20new%20separate%20domain%20for%20testing%20to%20minimize%20the%20impact%20on%20Production%3F%3C%2FP%3E%0A%3CP%3EIs%20there%20any%20Downtime%20involved%20in%20testing%3F%20Please%20advise.%3CBR%20%2F%3EPlease%20let%20me%20know%20if%20need%20more%20info.%20I%20will%20appreciate%20your%20response.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-175468%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-179656%22%20slang%3D%22en-US%22%3ERe%3A%20Plan%20to%20Test%20ADFS%20SSO%20with%20Production%20O365%20and%20to%20enable%20Federation%20in%20Production%20Azure%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-179656%22%20slang%3D%22en-US%22%3E%3CP%3EThanks!%3C%2FP%3E%0A%3CP%3EI%20will%20check%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-178427%22%20slang%3D%22en-US%22%3ERe%3A%20Plan%20to%20Test%20ADFS%20SSO%20with%20Production%20O365%20and%20to%20enable%20Federation%20in%20Production%20Azure%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-178427%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Manmeet%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20test%20the%20federation%20in%20your%20%3CU%3Eproduction%20tenant%3C%2FU%3E%2C%20you%20should%20do%20the%20following.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E1.%20Register%20a%20new%20domain%20to%20your%20tenant.%20You%20can%20get%20one%20free%20from%20%3CA%20href%3D%22https%3A%2F%2Fwww.myo365.site%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ewww.myo365.site%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E2.%20Install%20and%20configure%20AD%20FS.%20You%20do%20not%20need%20to%20use%20AAD%20Connect%2C%20you%20can%26nbsp%3Bdo%20that%20manually.%20To%20test%2C%20you%20only%20need%20one%20server%2C%20for%20production%20you%20should%20have%20at%20least%202%20AD%20FS%20servers%20and%202%20proxy%20servers.%3C%2FP%3E%0A%3CP%3E3.%20Install%20Azure%20AD%20(Office%20365)%20powershell%20module%20on%20AD%20FS%20server%20using%20following%20PowerShell%20cmdlet%3A%3C%2FP%3E%0A%3CPRE%3EInstall-Module%20MSOnline%3C%2FPRE%3E%0A%3CP%3E4.%20Connect%20to%20Office%20365%3A%3C%2FP%3E%0A%3CPRE%3EConnect-MsolService%3C%2FPRE%3E%0A%3CP%3E5.%20Set%20the%20federation%20context%20to%20use%20the%26nbsp%3Bcurrent%20AD%20FS%20server%3A%3C%2FP%3E%0A%3CPRE%3ESet-MsolADFSContext%3C%2FPRE%3E%0A%3CP%3E6.%20Convert%20the%20domain%20to%20federated%3A%3C%2FP%3E%0A%3CPRE%3EConvert-MsolDomainToFederated%20-DomainName%20yourdomain.com%3C%2FPRE%3E%0A%3CP%3EAnd%20that's%20it%2C%20you%20are%20ready%20to%20test%3A%3C%2FP%3E%0A%3CP%3E1.%20Browse%20to%20%3CA%20href%3D%22https%3A%2F%2Fportal.office.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fportal.office.com%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E2.%20Enter%26nbsp%3B%3CU%3Eany%3C%2FU%3E%26nbsp%3Busername%20with%20the%20federated%20domain%2C%20such%20as%20someone%40yourdomain.com%20and%20click%20next.%20Now%20the%20Office%20365%20recognizes%20that%20the%20domain%20is%20federated%20and%20redirects%20you%20to%20your%20AD%20FS%20server.%3C%2FP%3E%0A%3CP%3E3.%20Login%20in%20as%20any%20user%20using%20your%20actual%20username%20%26amp%3B%20password.%20And%20if%20you%20have%20configured%20your%20browsers%20properly%2C%20the%20users%20will%20be%20logged%20in%20automatically.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESo%2C%20the%20only%20difference%20to%20full%20production%20configuration%20is%20that%20you%20first%20need%20to%20enter%20%22the%20wrong%20domain%22%20to%20get%20redirected%20to%20your%20AD%20FS.%20After%20testing%2C%20you%20can%20convert%20the%20domain%20back%20to%20standard%20and%20convert%20your%20production%20domain%20to%20federated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-176084%22%20slang%3D%22en-US%22%3ERe%3A%20Plan%20to%20Test%20ADFS%20SSO%20with%20Production%20O365%20and%20to%20enable%20Federation%20in%20Production%20Azure%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-176084%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Manmeet%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EJust%20a%20note%3A%20You%20need%20a%20separate%20domain%20name%20to%20test%205%20users.%20I%20you%20have%20your%20principal%20UPN%20an%20unique%20public%20domain%2C%20once%20you%20activate%20federation%20is%20for%20all%20users%20of%20that%20domain%20name.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-175717%22%20slang%3D%22en-US%22%3ERe%3A%20Plan%20to%20Test%20ADFS%20SSO%20with%20Production%20O365%20and%20to%20enable%20Federation%20in%20Production%20Azure%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-175717%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Nuno%20for%20your%20help.%20I%20will%20come%20back%20to%20you.%3CBR%20%2F%3EI%20am%20collecting%20requirements%20for%20all%20the%20things%20which%20need%20to%20be%20federated%20before%20running%20AAD%20Connector.%20To%20minimize%20the%20risk%2C%20I%20am%20using%20pilot%20group%20of%20few%20users.%20I%20will%20federate%20this%20pilot%20group%20and%20move%20on%20with%20other%20users%20after%20success%20of%20Pilot%20Federation.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-175482%22%20slang%3D%22en-US%22%3ERe%3A%20Plan%20to%20Test%20ADFS%20SSO%20with%20Production%20O365%20and%20to%20enable%20Federation%20in%20Production%20Azure%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-175482%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Manmeet%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20need%20more%20than%20one%20domain%20you%20will%20need%20%22%3CSPAN%3ESupportMultipleDomain%3C%2FSPAN%3E%22%20parameter.%20Please%20see%20the%20following%20article%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fabizerh%2F2013%2F02%2F05%2Fsupportmultipledomain-switch-when-managing-sso-to-office-365%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fabizerh%2F2013%2F02%2F05%2Fsupportmultipledomain-switch-when-managing-sso-to-office-365%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20want%20the%20xyz.com%20domain%20as%20primary%20you%20will%20need%20to%20change%20on%20Office%20365%20Portal.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-175480%22%20slang%3D%22en-US%22%3ERe%3A%20Plan%20to%20Test%20ADFS%20SSO%20with%20Production%20O365%20and%20to%20enable%20Federation%20in%20Production%20Azure%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-175480%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Nuno%20for%20quick%20reply.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERight%20now%20I%20have%202%20domains%20added%20in%20Azure%20Portal.%3C%2FP%3E%0A%3CP%3EAssume%3C%2FP%3E%0A%3CP%3Eabc.com%26nbsp%3B%20%3D%3D%3D%3D%3D%3D%3D%20is%20Primary%20%3D%3D%3D%3D%3DNot%20Federated%3C%2FP%3E%0A%3CP%3Exyz.com%26nbsp%3B%20%26nbsp%3B%3D%3D%3D%3D%3D%3D%3D%20is%20verified%26nbsp%3B%3CSPAN%3E%3D%3D%3D%3D%3DNot%20Federated%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eabc.com%20is%20in%20Production%20Use.%3C%2FP%3E%0A%3CP%3EMy%20goal%20is%20to%20federate%20%3CSTRONG%3Exyz.com%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EWhile%20installing%20AAD%20Connect%2C%20if%20i%20choose%20xyz.com%20for%20federation%2C%20will%20it%20become%20Primary%20also%3F%3C%2FP%3E%0A%3CP%3EPlease%20clarify.%20Thanks.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-175476%22%20slang%3D%22en-US%22%3ERe%3A%20Plan%20to%20Test%20ADFS%20SSO%20with%20Production%20O365%20and%20to%20enable%20Federation%20in%20Production%20Azure%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-175476%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Manmeet%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20have%20your%20public%20domain%20in%20production%20please%20follow%20the%20steps%20in%20the%20following%20article%20to%20enable%20ADFS%20to%20Office%20365%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fcanitpro%2F2015%2F09%2F11%2Fstep-by-step-setting-up-ad-fs-and-enabling-single-sign-on-to-office-365%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fcanitpro%2F2015%2F09%2F11%2Fstep-by-step-setting-up-ad-fs-and-enabling-single-sign-on-to-office-365%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20testing%20you%20will%20need%20to%20create%20a%20separate%20environment%20to%20other%20Office%20365%20Tenant.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20downtime%20is%20almost%200%20because%20after%20you%20enable%20it%20it's%20seconds.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20follow%20this%20article%20also%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Frmilne%2F2017%2F05%2F14%2Fhow-to-install-ad-fs-2016-for-office-365-part-3%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Frmilne%2F2017%2F05%2F14%2Fhow-to-install-ad-fs-2016-for-office-365-part-3%2F%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Manmeet Singh
Occasional Contributor

Hi Team,

 

I have setup ADFS SSO for on-premises and integrated it with Azure Traffic Manager.

Now i need to use ADFS SSO with O365 Portal, it means i need to enable federated identity.

Azure AD Connect is already enabled and sync is working for a domain in Azure Portal.

Risk Factor is O365 Portal is in Production use and on-premises AD is already in sync.

Can you please advise how i Plan to Test ADFS SSO with Production Office 365?

Should i add a new separate domain for testing to minimize the impact on Production?

Is there any Downtime involved in testing? Please advise.
Please let me know if need more info. I will appreciate your response.

 

7 Replies

Hi Manmeet,

 

If you have your public domain in production please follow the steps in the following article to enable ADFS to Office 365 https://blogs.technet.microsoft.com/canitpro/2015/09/11/step-by-step-setting-up-ad-fs-and-enabling-s...

 

For testing you will need to create a separate environment to other Office 365 Tenant.

 

The downtime is almost 0 because after you enable it it's seconds.

 

You can follow this article also https://blogs.technet.microsoft.com/rmilne/2017/05/14/how-to-install-ad-fs-2016-for-office-365-part-...

Thanks Nuno for quick reply.

 

Right now I have 2 domains added in Azure Portal.

Assume

abc.com  ======= is Primary =====Not Federated

xyz.com   ======= is verified =====Not Federated

 

abc.com is in Production Use.

My goal is to federate xyz.com

While installing AAD Connect, if i choose xyz.com for federation, will it become Primary also?

Please clarify. Thanks.

 

Hi Manmeet,

 

If you need more than one domain you will need "SupportMultipleDomain" parameter. Please see the following article https://blogs.technet.microsoft.com/abizerh/2013/02/05/supportmultipledomain-switch-when-managing-ss...

 

If you want the xyz.com domain as primary you will need to change on Office 365 Portal.

Thanks Nuno for your help. I will come back to you.
I am collecting requirements for all the things which need to be federated before running AAD Connector. To minimize the risk, I am using pilot group of few users. I will federate this pilot group and move on with other users after success of Pilot Federation.

Hi Manmeet,

 

Just a note: You need a separate domain name to test 5 users. I you have your principal UPN an unique public domain, once you activate federation is for all users of that domain name.

Hi Manmeet,

 

To test the federation in your production tenant, you should do the following.

 

1. Register a new domain to your tenant. You can get one free from www.myo365.site

2. Install and configure AD FS. You do not need to use AAD Connect, you can do that manually. To test, you only need one server, for production you should have at least 2 AD FS servers and 2 proxy servers.

3. Install Azure AD (Office 365) powershell module on AD FS server using following PowerShell cmdlet:

Install-Module MSOnline

4. Connect to Office 365:

Connect-MsolService

5. Set the federation context to use the current AD FS server:

Set-MsolADFSContext

6. Convert the domain to federated:

Convert-MsolDomainToFederated -DomainName yourdomain.com

And that's it, you are ready to test:

1. Browse to https://portal.office.com

2. Enter any username with the federated domain, such as someone@yourdomain.com and click next. Now the Office 365 recognizes that the domain is federated and redirects you to your AD FS server.

3. Login in as any user using your actual username & password. And if you have configured your browsers properly, the users will be logged in automatically.

 

So, the only difference to full production configuration is that you first need to enter "the wrong domain" to get redirected to your AD FS. After testing, you can convert the domain back to standard and convert your production domain to federated.

Related Conversations
Azure Files with adfs
Stephane KLOIS in Azure on
0 Replies
Third party Login - SSO
Eladio José Cousiño Godoy in Azure on
0 Replies
ADFS SSO sign-in as different user
Gurdev Singh in Azure Active Directory on
4 Replies
Azure AD Federated with AD FS Issue
YU Yang in Azure Active Directory on
4 Replies
Urgent - Teams and Yealink
reditguy in Microsoft Teams on
4 Replies