Force OneDrive client to sign into a different tenant

%3CLINGO-SUB%20id%3D%22lingo-sub-267697%22%20slang%3D%22en-US%22%3EForce%20OneDrive%20client%20to%20sign%20into%20a%20different%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267697%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20going%20through%20a%20merger%2C%20and%20as%20part%20of%20that%20must%20migrate%20our%20users%20from%20TenantA%20to%20TenantB.%26nbsp%3B%20Currently%20we%20have%20separate%20AD%20domains%20and%20SSO%20platforms%2C%20though%20there%20is%20some%20federation%20(I'm%20not%20100%25%20clear%20on%20the%20details).%26nbsp%3B%20We%20have%20a%20fair%20number%20of%20users%20who%20have%20not%20yet%20gotten%20on%20board%20with%20OneDrive%2C%20so%20rather%20than%20get%20them%20setup%20in%20TenantA%2C%20we'd%20like%20to%20push%20them%20over%20to%20TenantB%20right%20off%20the%20bat.%26nbsp%3B%20If%20I%20go%20to%20tenantb-my.sharepoint.com%20and%20sign-in%20with%20my%20user%40domainA.com%20credentials%2C%20I%20am%20able%20to%20view%20my%20OneDrive%20in%20TenantB%20(this%20was%20setup%20on%20our%20independent%20authentication%20SSO%20system%20and%20works%20fine).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20problem%20we're%20facing%20however%20is%20to%20force%20the%20user%20to%20connect%20to%20TenantB%20via%20the%20OneDrive%20client.%26nbsp%3B%20If%20they%20use%20user%40domainB.com%20on%20the%20%22Sign%20in%20to%20OneDrive%22%20window%2C%20we%20get%20an%20authentication%20error%20that%20we%20need%20to%20sign%20in%20with%20domainA%20credentials.%20If%20I%20use%20user%40domainA.com%2C%20then%20it%20tries%20(and%20fails)%20to%20setup%20the%20OneDrive%20in%20TenantA%20(which%20is%20blocked%20by%20the%20%22only%20allow%20certain%20tenants%22%20GPO%2C%20mentioned%20below).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20tried%20using%20the%20various%20GPO%20settings%20to%20force%20the%20OD%20client%20to%20only%20connect%20to%20TenantB.%26nbsp%3B%20I've%20tried%20onedrive.exe%20%2Fconfigure_business%3AtenantB-GUID%2C%20set%20EnableADAL%20(why%20isn't%20this%20a%20GPO%20option%20yet%2C%20btw!)%2C%20Silent%20AutoConfig%20(with%20the%20requisite%20max%20OD%20size%20configured)%2C%20but%20no%20matter%20what%20I%20do%2C%20OD%20always%20pops%20up%20with%20the%20%22Enter%20your%20email%20address%22.%26nbsp%3B%20Is%20there%20some%20other%20way%20to%20call%20onedrive.exe%20so%20that%20it%20suppresses%20the%20sign-in%20dialog%2C%20something%20like%3A%3C%2FP%3E%3CPRE%3Eonedrive.exe%20%2Fconfigure_business%3AtenantGBuid%20%2Fuseremail%3Auser%40domainA.com%20%2Fsilent%20%2FURL%3Ahttps%3A%2F%2Ftenantb-my.sharepoint.com%3C%2FPRE%3E%3CP%3EAm%20I%20maybe%20just%20coming%20up%20against%20a%20limitation%20of%20the%20OD%20client%20and%20how%20it%20can%20be%20manipulated%20to%20login%20to%20a%20specific%20tenant%3F%26nbsp%3B%20I'm%20even%26nbsp%3Btried%26nbsp%3Bpre-creating%26nbsp%3Ba%20Business1%20account%20entry%20at%26nbsp%3B%20HKCU%5CSoftware%5CMicrosoft%5COneDrive%5CAccounts%5CBusiness1%5C%26nbsp%3B%20with%20various%20fields%20pre-configured%2C%20like%20UserEmail%20%3D%20user%40domainA.com%20or%20something%20(though%20that%20didn't%20work%20either%3B%20OD%20trashed%20the%20Business1%20key%20and%20created%20it%20fresh%20when%20it%20tried%20to%20sign%20in).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-267697%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOneDrive%20for%20Business%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESync%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-275416%22%20slang%3D%22en-US%22%3ERe%3A%20Force%20OneDrive%20client%20to%20sign%20into%20a%20different%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-275416%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F8017%22%20target%3D%22_blank%22%3E%40KYLE%20SCHROEDER%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESorry%20for%20the%20delay!%20The%20team%20is%20taking%20a%20look%20and%20may%20need%20additional%20details.%20It%20looks%20like%20the%20support%20case%20is%20still%20active%20as%20well%20so%20let's%20use%20that%20to%20engage%20%26amp%3B%20discuss.%20Thanks!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EStephen%20Rice%3C%2FP%3E%0A%3CP%3EOneDrive%20Program%20Manager%20II%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-272302%22%20slang%3D%22en-US%22%3ERe%3A%20Force%20OneDrive%20client%20to%20sign%20into%20a%20different%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-272302%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F181%22%20target%3D%22_blank%22%3E%40Stephen%20Rice%3C%2FA%3E%26nbsp%3Bhave%20you%20heard%20back%20from%20the%20tech%20team%3F%26nbsp%3B%20I%20have%20a%20support%20case%20open%20on%20this%20as%20well%2C%26nbsp%3B118101519225226%2C%20though%20it%20seems%20to%20be%20more%20of%20a%20feature%20change%20than%20anything%20that%20is%20due%20to%20a%20%22broken%22%20client.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-269585%22%20slang%3D%22en-US%22%3ERe%3A%20Force%20OneDrive%20client%20to%20sign%20into%20a%20different%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-269585%22%20slang%3D%22en-US%22%3EAny%20news%20Stephen%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268554%22%20slang%3D%22en-US%22%3ERe%3A%20Force%20OneDrive%20client%20to%20sign%20into%20a%20different%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268554%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20don't%20have%20the%20key%20but%20let%20me%20pass%20this%20along%20to%20some%20of%20our%20area%20experts%20and%20see%20what%20we%20have.%20Thanks%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EStephen%20Rice%3C%2FP%3E%0A%3CP%3EOneDrive%20Program%20Manager%20II%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268257%22%20slang%3D%22en-US%22%3ERe%3A%20Force%20OneDrive%20client%20to%20sign%20into%20a%20different%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268257%22%20slang%3D%22en-US%22%3EGreat%2C%20thanks%20Juan%20Carlos%20for%20tagging%20Stephen.%20Hoping%20he%20has%20the%20key!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-267758%22%20slang%3D%22en-US%22%3ERe%3A%20Force%20OneDrive%20client%20to%20sign%20into%20a%20different%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267758%22%20slang%3D%22en-US%22%3E%3CP%3EI%20think%20the%20best%20person%20that%20can%20help%20here%20is%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F181%22%20target%3D%22_blank%22%3E%40Stephen%20Rice%3C%2FA%3E.%20For%20sure%20he%20will%20point%20out%20to%20the%20right%20people%20that%20can%20support%20you%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-770385%22%20slang%3D%22en-US%22%3ERe%3A%20Force%20OneDrive%20client%20to%20sign%20into%20a%20different%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-770385%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F181%22%20target%3D%22_blank%22%3E%40Stephen%20Rice%3C%2FA%3E%26nbsp%3B%20at%20this%20point%20our%20best%20option%20is%20to%20launch%20OD%20as%20follows%20(i.e.%20from%20a%20Batch%20file)%3A%3CBR%20%2F%3Estart%20odopen%3A%2F%2Fsync%2F%3FuserEmail%3Dfirstname.lastname%40domain.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20are%20some%20other%20parameters%20to%20odopen%3A%2F%2F%20URLs%2C%20but%20for%20now%2C%20this%20is%20sufficient.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

We are going through a merger, and as part of that must migrate our users from TenantA to TenantB.  Currently we have separate AD domains and SSO platforms, though there is some federation (I'm not 100% clear on the details).  We have a fair number of users who have not yet gotten on board with OneDrive, so rather than get them setup in TenantA, we'd like to push them over to TenantB right off the bat.  If I go to tenantb-my.sharepoint.com and sign-in with my user@domainA.com credentials, I am able to view my OneDrive in TenantB (this was setup on our independent authentication SSO system and works fine).

 

The problem we're facing however is to force the user to connect to TenantB via the OneDrive client.  If they use user@domainB.com on the "Sign in to OneDrive" window, we get an authentication error that we need to sign in with domainA credentials. If I use user@domainA.com, then it tries (and fails) to setup the OneDrive in TenantA (which is blocked by the "only allow certain tenants" GPO, mentioned below).

 

I've tried using the various GPO settings to force the OD client to only connect to TenantB.  I've tried onedrive.exe /configure_business:tenantB-GUID, set EnableADAL (why isn't this a GPO option yet, btw!), Silent AutoConfig (with the requisite max OD size configured), but no matter what I do, OD always pops up with the "Enter your email address".  Is there some other way to call onedrive.exe so that it suppresses the sign-in dialog, something like:

onedrive.exe /configure_business:tenantGBuid /useremail:user@domainA.com /silent /URL:https://tenantb-my.sharepoint.com

Am I maybe just coming up against a limitation of the OD client and how it can be manipulated to login to a specific tenant?  I'm even tried pre-creating a Business1 account entry at  HKCU\Software\Microsoft\OneDrive\Accounts\Business1\  with various fields pre-configured, like UserEmail = user@domainA.com or something (though that didn't work either; OD trashed the Business1 key and created it fresh when it tried to sign in).

7 Replies

I think the best person that can help here is @Stephen Rice. For sure he will point out to the right people that can support you

Great, thanks Juan Carlos for tagging Stephen. Hoping he has the key!

Hi all,

 

I don't have the key but let me pass this along to some of our area experts and see what we have. Thanks,

 

Stephen Rice

OneDrive Program Manager II

Any news Stephen?

@Stephen Rice have you heard back from the tech team?  I have a support case open on this as well, 118101519225226, though it seems to be more of a feature change than anything that is due to a "broken" client.

Hi @KYLE SCHROEDER,

 

Sorry for the delay! The team is taking a look and may need additional details. It looks like the support case is still active as well so let's use that to engage & discuss. Thanks!

 

Stephen Rice

OneDrive Program Manager II

@Stephen Rice  at this point our best option is to launch OD as follows (i.e. from a Batch file):
start odopen://sync/?userEmail=firstname.lastname@domain.com

 

There are some other parameters to odopen:// URLs, but for now, this is sufficient.