SSO in Office 365 ProPlus with SCA (Shared Computer Activation)

%3CLINGO-SUB%20id%3D%22lingo-sub-36293%22%20slang%3D%22en-US%22%3ESSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-36293%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20find%20very%20little%20information%20on%20SSO%20into%20Office%20365%20ProPlus%20when%20it%20is%20deployed%20using%20SCA.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EShould%20it%20be%20possible%20for%20a%20user%20to%20log%20into%20Windows%20(domain%20joined%2C%20AADSync%2C%20no%20roaming%20profiles)%3C%2FP%3E%3CP%3Eand%20be%20logged%20in%20automatically%20into%20Office%20ProPlus%3C%2FP%3E%3CP%3Eor%26nbsp%3Bwill%20he%20always%20have%20to%20enter%20his%20credentials%20as%20well%20in%20Office%20ProPlus%20(deployed%20using%20SCCM%20with%20Shared%20Computer%20Activation)%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBart%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-36293%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-44433%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-44433%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Peter.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20I%20don't%20see%20anywhere%26nbsp%3Bin%20that%20article%20mentioning%20about%20excluding%20those%20folders%20or%20am%20I%20really%20not%20reading%20it%20right%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20AppData%2FLocal%20folder%20is%20not%20redirected%2C%20only%20AppData%5CRoaming%20folder%20is%20redirected%20but%20license%20tokens%20are%20not%20saved%26nbsp%3Bin%20there.%20So%20I%20am%20not%20sure%20what%20is%20causing%20this.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20met%20another%20guy%20from%20a%20company%20who%20used%20to%20have%20the%20same%20issue%20with%20their%20client%20and%20they%20just%20told%20the%20clients%20that%20they%20are%20required%20to%20sign-in%26nbsp%3Bevery%20day%20coz%20they%20couldnt%20find%20the%20cause%20of%20it.%20But%20lack%20of%26nbsp%3Bposts%20regarding%20this%20issue%20on%20the%20Internet%20tells%20me%20either%20we%20are%20doing%20something%20so%20wrong%20(even%20though%20we%20configure%20it%20using%20Microsoft%20whitepaper)%20or%20this%20is%20the%20way%20it%20is%20supposed%20to%20work!%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43887%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43887%22%20slang%3D%22en-US%22%3EI%20don%60t%20remember%20the%20exact%20issue%20that%20customer%20was%20having%20with%20their%20Office%20license%20on%20a%20RDS%20farm%20(they%20had%202%20issues)%2C%20but%20because%20the%20MS%20articles%20talk%20about%20excluding%20%25localappdata%25%5C...%20and%20that%20did%20not%20work%2C%20but%20using%20%5C%5CAppdata%5CLocal%5C...%20was%20working%2C%20I%20thought%20it%20is%20worth%20to%20mention%20it.%3CBR%20%2F%3E%3CBR%20%2F%3EBut%20yes%2C%20you%20need%20to%20exclude%20that%20from%20redirecting%20when%20using%20User%20Profile%20disks%20or%20roaming%20profiles.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43851%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43851%22%20slang%3D%22en-US%22%3EHi%20Peter%2C%3CBR%20%2F%3E%3CBR%20%2F%3EAre%20you%20saying%20that%20folder%20needs%20to%20be%20excluded%20from%20the%20redirected%20folders%3F%26nbsp%3B%20I've%20seen%20the%20article%20but%20I%20didn't%20find%20enough%20information%20in%20it%20for%20the%20issue%20we're%20having.%20Thanks%20again%20for%20your%20reply.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43798%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43798%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F11762%22%20target%3D%22_blank%22%3E%40Madhu%20Perera%3C%2FA%3E%3C%2FP%3E%3CP%3ESeen%20this%20article%3F%20%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn782859.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn782859.aspx%3C%2FA%3E%3C%2FP%3E%3CP%3EIf%20using%20roamig%20profiles%2C%20exclude%20this%20location%20%5CAppData%5CLocal%5CMicrosoft%5COffice%5C16.0%5CLicensing%20and%20don%60t%20use%20%25localAppData%25%5CMicrosoft%5COffice%5C16.0%5CLicensing%20to%20exclude%3CBR%20%2F%3EHave%20seen%20license%20issues%20on%20RDS%20farm%20at%20a%20customer%2C%20who%20was%20excluding%20%25localAppData%25%5CMicrosoft%5COffice%5C16.0%5CLicensing%20on%20request%20of%20a%20Microsoft%20engeineer%2C%20when%20changed%20to%20%5CAppData%5CLocal%5CMicrosoft%5COffice%5C16.0%5CLicensing%20it%20al%20worked%20fine.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-41308%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-41308%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Sonia%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20deployed%20Office%20365%20ProPlus%20on%20Remote%20Desktop%20Servers%20for%20few%20of%20our%20clients.%20All%20of%20them%20are%26nbsp%3Bgetting%20prompted%20to%20re-authenticate%20every%20now%20and%20then.%20One%26nbsp%3Bof%20the%20clients%20has%20no%20proxy%26nbsp%3Beither%20but%20they%20are%20always%20prompted%20to%26nbsp%3Bre-authenticate%20every%2030-40%20days%20on%20their%20terminal%20server.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20you%26nbsp%3Bseen%20or%20heard%20about%20this%20behaviour%20before%3F%20It%20is%20a%20pain%20for%20the%20clients%20with%20a%20large%20number%20of%20Terminal%20Server%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMadhu%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-36367%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-36367%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20the%20feedback!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20would%20be%20very%20unfortunate%20because%20the%20reason%20of%20using%20SCA%20is%20that%20users%20are%20always%20using%20another%20PC%20to%20work%20on.%20So%20If%20I%20understand%20it%20correctly%2C%20they%20will%20always%20have%20to%20go%20through%20the%20Office%20authentication%20flow%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20the%20documentation%20I%20found%20and%20also%20on%20the%20video%20about%20Office%20deployment%2C%20the%20message%20is%20given%20that%20the%20user%20is%20authenticated%20automatically%20in%20the%20background%20without%20dialog%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EIf%20your%20environment%20is%20configured%20to%20synchronize%20Office%20365%20and%20network%20user%20accounts%2C%20then%20the%20user%20probably%20won't%20see%20any%20prompts.%20Office%20365%20ProPlus%20should%20automatically%20be%20able%20to%20get%20the%20necessary%20information%20about%20the%20user's%20account%20in%20Office%20365.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn782860.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CFONT%20color%3D%22%230000ff%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn782860.aspx%3C%2FFONT%3E%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20same%20message%20is%20said%20in%20the%20MVA%20video%3A%20%3CA%20href%3D%22https%3A%2F%2Fmva.microsoft.com%2Fen-US%2Ftraining-courses%2Fsolving-office-365-client-deployment-scenarios-9086%3Fl%3DsuttZBf4_2304984382%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fmva.microsoft.com%2Fen-US%2Ftraining-courses%2Fsolving-office-365-client-deployment-scenarios-9086%3Fl%3DsuttZBf4_2304984382%3C%2FA%3E%3C%2FP%3E%3CP%3Eat%2000%3A34%3A00%20but%20they%20don't%20succeed%20in%20demoing%20it...%20%22With%20ADFS%20it%20will%20be%20seamless%2C%20you%20won't%20be%20prompted%20for%20a%20login%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-36348%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-36348%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20addition%20to%20Bill's%20comments%2C%20that%20log%20in%20and%20activation%20should%20only%20appear%20on%20first%20use.%3C%2FP%3E%3CP%3EThe%20licensing%20token%20system%20means%20every%20time%20after%20that%2C%20the%20background%20process%20will%20contact%20the%20licensing%20server%20and%20attempt%20to%20renew%20the%20token%20in%20the%20backgorund%2C%20without%20the%20need%20for%20additional%20username%20and%20password%20entering%20by%20the%20user.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-Sonia%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-36307%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-36307%22%20slang%3D%22en-US%22%3E%3CP%3EWith%20Shared%20Computer%20Activation%20the%20user%20is%20always%20prompted%20for%20their%20username%20on%20first%20launch.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20Federated%20Authentication%20(SSO)%20it%20is%20possible%20to%20remove%20the%20requirement%20for%20them%20to%20enter%20their%20password%20and%20only%20require%20them%20to%20enter%20their%20username%20at%20which%20point%20the%20authentication%20dialog%20will%20redirect%20them%20to%20your%20federated%20sign%20on%20page%20which%20would%20automatically%20sign%20them%20in.%20If%20however%20a%20individual%20users%20first%20use%20on%20a%20machine%20occurs%20outside%20the%20network%20this%20would%20not%20happen%20as%20most%26nbsp%3Bfederated%20authentication%20deployments%20present%20forms%20based%20authentication%20to%20all%20external%20off%20network%20devices.%20(Remote%20Desktop%20is%20generally%20still%20inside%20the%20network%20from%20a%20federated%20authentication%20perspective)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20SCA%20first%20time%20user%20experience%20is%20documented%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn782860.aspx%23How%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn782860.aspx%23How%3C%2FA%3E%20shared%20computer%20activation%20works%20for%20Office%20365%20ProPlus%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1621496%22%20slang%3D%22en-US%22%3ERe%3A%20SSO%20in%20Office%20365%20ProPlus%20with%20SCA%20(Shared%20Computer%20Activation)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1621496%22%20slang%3D%22en-US%22%3E%3CP%3EI%20know%20this%20is%20old%20post%20but..%3C%2FP%3E%3CP%3EI%20believe%20they%20are%20referring%20to%20the%20exclusion%20list%20for%20local%20app%20data%20by%20adding%20the%20path%20the%20the%20exclusion%20to%20allow%20it%20to%20propagate%20as%20part%20of%20roaming%20profile.%3C%2FP%3E%3CP%3EExample%20here%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2F4sysops.com%2Farchives%2Finclude-and-exclude-folders-in-roaming-user-profiles%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2F4sysops.com%2Farchives%2Finclude-and-exclude-folders-in-roaming-user-profiles%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F11762%22%20target%3D%22_blank%22%3E%40Madhu%20Perera%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Super Contributor

Hello,

 

I find very little information on SSO into Office 365 ProPlus when it is deployed using SCA.

 

Should it be possible for a user to log into Windows (domain joined, AADSync, no roaming profiles)

and be logged in automatically into Office ProPlus

or will he always have to enter his credentials as well in Office ProPlus (deployed using SCCM with Shared Computer Activation)?

 

Bart

9 Replies

With Shared Computer Activation the user is always prompted for their username on first launch.

 

With Federated Authentication (SSO) it is possible to remove the requirement for them to enter their password and only require them to enter their username at which point the authentication dialog will redirect them to your federated sign on page which would automatically sign them in. If however a individual users first use on a machine occurs outside the network this would not happen as most federated authentication deployments present forms based authentication to all external off network devices. (Remote Desktop is generally still inside the network from a federated authentication perspective)

 

The SCA first time user experience is documented here: https://technet.microsoft.com/en-us/library/dn782860.aspx#How shared computer activation works for Office 365 ProPlus 

In addition to Bill's comments, that log in and activation should only appear on first use.

The licensing token system means every time after that, the background process will contact the licensing server and attempt to renew the token in the backgorund, without the need for additional username and password entering by the user.

 

-Sonia

Thank you the feedback!

 

That would be very unfortunate because the reason of using SCA is that users are always using another PC to work on. So If I understand it correctly, they will always have to go through the Office authentication flow?

 

In the documentation I found and also on the video about Office deployment, the message is given that the user is authenticated automatically in the background without dialog:

 

If your environment is configured to synchronize Office 365 and network user accounts, then the user probably won't see any prompts. Office 365 ProPlus should automatically be able to get the necessary information about the user's account in Office 365.

 

From https://technet.microsoft.com/en-us/library/dn782860.aspx

 

The same message is said in the MVA video: https://mva.microsoft.com/en-US/training-courses/solving-office-365-client-deployment-scenarios-9086...

at 00:34:00 but they don't succeed in demoing it... "With ADFS it will be seamless, you won't be prompted for a login"

 

Hi Sonia,

 

We have deployed Office 365 ProPlus on Remote Desktop Servers for few of our clients. All of them are getting prompted to re-authenticate every now and then. One of the clients has no proxy either but they are always prompted to re-authenticate every 30-40 days on their terminal server.

 

 

Have you seen or heard about this behaviour before? It is a pain for the clients with a large number of Terminal Server users.

 

Thanks in advance.

 

Madhu

Hi @Madhu Perera

Seen this article? https://technet.microsoft.com/en-us/library/dn782859.aspx

If using roamig profiles, exclude this location \AppData\Local\Microsoft\Office\16.0\Licensing and don`t use %localAppData%\Microsoft\Office\16.0\Licensing to exclude
Have seen license issues on RDS farm at a customer, who was excluding %localAppData%\Microsoft\Office\16.0\Licensing on request of a Microsoft engeineer, when changed to \AppData\Local\Microsoft\Office\16.0\Licensing it al worked fine.

Hi Peter,

Are you saying that folder needs to be excluded from the redirected folders?  I've seen the article but I didn't find enough information in it for the issue we're having. Thanks again for your reply.
I don`t remember the exact issue that customer was having with their Office license on a RDS farm (they had 2 issues), but because the MS articles talk about excluding %localappdata%\... and that did not work, but using \\Appdata\Local\... was working, I thought it is worth to mention it.

But yes, you need to exclude that from redirecting when using User Profile disks or roaming profiles.

Thanks Peter.

 

However I don't see anywhere in that article mentioning about excluding those folders or am I really not reading it right :)

 

Also AppData/Local folder is not redirected, only AppData\Roaming folder is redirected but license tokens are not saved in there. So I am not sure what is causing this.

 

 

I met another guy from a company who used to have the same issue with their client and they just told the clients that they are required to sign-in every day coz they couldnt find the cause of it. But lack of posts regarding this issue on the Internet tells me either we are doing something so wrong (even though we configure it using Microsoft whitepaper) or this is the way it is supposed to work!?

I know this is old post but..

I believe they are referring to the exclusion list for local app data by adding the path the the exclusion to allow it to propagate as part of roaming profile.

Example here 

https://4sysops.com/archives/include-and-exclude-folders-in-roaming-user-profiles/

 

@Madhu Perera