Forum Discussion
The new Azure AD sign-in and “Keep me signed in” experiences rolling out now!
I'm not familiar with how SharePoint handles internal vs external sites. I would recommend that you contact Office 365 or SharePoint support to help you with that. They would be the best resource to help you here.
Sorry I'm a little late to the party, but I just didn't have time back when the thread started and I kind of forgot about it. But now that I've read through all the 3 pages I'm chiming in with my issues:
Our SSO with Chrome and IE worked fine somewhere last year. Probably due to these changes it stopped working flawlessly, but not completely.
My setup consisted of configured Trusted Zones, ADFS on 2012R2 (I remember doing something to get this working for Chrome on ADFS 2 years ago), MFA exemption for onPrem IP Range, AAD-Connect and some URL tricks, like using the WHR parameter (https://login.microsoftonline.com/?whr=mycustomdomain.com)
Then it stopped working flawlessly, and degraded to having to click the pre-populated UPN and getting automatically signed in again after every browser closure.
I believe to have improved the experience, by dropping the WHR parameter, after which the users only had to click the pre-populated UPN about once a day.
This is also my current status, as far as I remember. I've noticed that when I leave my computer running over night (no standby) and return in the morning, I'm signed out of office.com or other pages. There is a sign in button on that office.com sign out portal and when I click it, I'm automatically signed in again after a few redirects without further input. A negative side effect of all this is, that on the first browser open any additional Sharepoint sites are not opened automatically, since the first site hasn't fully authenticated yet.
SSO seems wo work with no issues on my home computer (Mac/Safari) where I get all the KMSI and MFA prompts and I stay signed for multiple weeks.
By reading through everything here I'll start digging in into the ADFS configuration (and this article https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/ad-fs-single-sign-on-settings), but I'll appreciate any shortcuts you guys have to offer :)