General SSO Office 365 Authentication Issues

%3CLINGO-SUB%20id%3D%22lingo-sub-174159%22%20slang%3D%22en-US%22%3EGeneral%20SSO%20Office%20365%20Authentication%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-174159%22%20slang%3D%22en-US%22%3E%3CP%3EAfter%20rolling%20out%20Office%20365%20and%20federating%20with%20Okta%20its%20seems%20to%20be%20very%20unstable%20as%20far%20as%20holding%20peoples%20sessions%20(mainly%20to%20OWA)%20Wondering%20if%20anyone%20has%20any%20advice.%20I%20do%20not%20remember%20having%20these%20issues%20with%20the%20old%20sign%20in%20experience%20from%20Microsoft.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHere%20are%20a%20few%20details%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOWA%20is%20not%20holding%20sessions%20for%20very%20long%20and%20sometimes%20folks%20get%20session%20timeout%20messages.%20On%20google%20the%20sessions%20held%20for%20several%20days%20even%20if%20the%20machine%20or%20browser%20was%20closed.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOutlook%202016%20is%20constantly%20prompting%20people%20to%20log%20back%20in%20to%20Okta%20which%20is%20a%20more%20recent%20issue.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20general%2C%20it%20seems%20like%20people%20are%20constantly%20having%20to%20login%20to%20SSO%20for%20various%20office%20365%20apps.%20I%20do%20not%20believe%20its%20an%20Okta%20issue%20as%20thats%20only%20getting%20presented%20after%20users%20are%20kicked%20out%20of%20Office%20365.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-174159%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-174694%22%20slang%3D%22en-US%22%3ERe%3A%20General%20SSO%20Office%20365%20Authentication%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-174694%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20would%20be%20best%20to%20open%20a%20support%20case%20for%20this%20as%20it%20isn't%20clear%20that%20it's%20directly%20related%20to%20the%20new%20sign-in%20experience.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-174415%22%20slang%3D%22en-US%22%3ERe%3A%20General%20SSO%20Office%20365%20Authentication%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-174415%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20mean%20that%20the%20issue%20started%20occurring%20after%20they%20introduced%20the%20new%20sign-in%20page%2C%20I%20agree%2C%20that's%20most%20likely%20something%20on%20O365's%20side.%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F70095%22%20target%3D%22_blank%22%3E%40Kelvin%20Xia%3C%2FA%3E%26nbsp%3Bmight%20be%20able%20to%20help%20with%20that.%20Or%20better%20yet%2C%20open%20a%20support%20case.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-174241%22%20slang%3D%22en-US%22%3ERe%3A%20General%20SSO%20Office%20365%20Authentication%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-174241%22%20slang%3D%22en-US%22%3EI%20guess%20where%20Im%20confused%20is%20that%20its%20kicking%20people%20out%20then%20redirecting%20back%20to%20Okta.%20We%20have%20around%2015%20other%20apps%20in%20Okta%20that%20all%20use%20the%20same%20setting%20and%20have%200%20issues.%20I%20had%20office%20365%20on%20the%20classic%20sign%20in%20experience%20SSOed%20through%20Okta%20for%20a%20while%20and%20also%20did%20not%20have%20any%20issues%20what-so-ever.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-174214%22%20slang%3D%22en-US%22%3ERe%3A%20General%20SSO%20Office%20365%20Authentication%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-174214%22%20slang%3D%22en-US%22%3E%3CP%3EThat%20looks%20like%20the%20type%20of%20issue%20you%20have%20to%20address%20with%20Okta%20support.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20default%20O365%20session%20timeouts%20are%20listed%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2Fsession-timeouts-for-office-365-37a5c116-5b07-4f70-8333-5b86fd2c3c40%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2Fsession-timeouts-for-office-365-37a5c116-5b07-4f70-8333-5b86fd2c3c40%3C%2FA%3E%3C%2FP%3E%0A%3CP%3ESome%20of%20these%20can%20be%20modified%20on%20the%20customer%20side%20(i.e.%20the%20OWA%20timeout)%2C%20but%20they%26nbsp%3Bare%20all%26nbsp%3Bdependent%20on%20the%20identity%20provider%20(Okta%20in%20your%20case).%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

After rolling out Office 365 and federating with Okta its seems to be very unstable as far as holding peoples sessions (mainly to OWA) Wondering if anyone has any advice. I do not remember having these issues with the old sign in experience from Microsoft.

 

Here are a few details:

 

OWA is not holding sessions for very long and sometimes folks get session timeout messages. On google the sessions held for several days even if the machine or browser was closed. 

 

Outlook 2016 is constantly prompting people to log back in to Okta which is a more recent issue. 

 

In general, it seems like people are constantly having to login to SSO for various office 365 apps. I do not believe its an Okta issue as thats only getting presented after users are kicked out of Office 365. 

 

 

4 Replies
Highlighted

That looks like the type of issue you have to address with Okta support.

 

The default O365 session timeouts are listed here: https://support.office.com/en-us/article/session-timeouts-for-office-365-37a5c116-5b07-4f70-8333-5b8...

Some of these can be modified on the customer side (i.e. the OWA timeout), but they are all dependent on the identity provider (Okta in your case).

Highlighted
I guess where Im confused is that its kicking people out then redirecting back to Okta. We have around 15 other apps in Okta that all use the same setting and have 0 issues. I had office 365 on the classic sign in experience SSOed through Okta for a while and also did not have any issues what-so-ever.
Highlighted

If you mean that the issue started occurring after they introduced the new sign-in page, I agree, that's most likely something on O365's side. @Kelvin Xia might be able to help with that. Or better yet, open a support case.

Highlighted

It would be best to open a support case for this as it isn't clear that it's directly related to the new sign-in experience.