SharePoint online single sign on with on-premise AD

%3CLINGO-SUB%20id%3D%22lingo-sub-2699363%22%20slang%3D%22en-US%22%3ESharePoint%20online%20single%20sign%20on%20with%20on-premise%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2699363%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20planning%20to%20implement%20intranet%20on%20SharePoint%20Online.%20Currently%2C%20the%20office%20365%20apps%20%26amp%3B%20SharePoint%20authentication%20is%20based%20on%20Azure%20AD%20which%20is%20office%20365%20email%20%26amp%3B%20password.%20However%2C%20we%20want%20to%20use%20on-Premise%20AD%20domain%20username%20and%20password%20for%20single%20sign-on.%20Our%20IT%20syncs%20only%20the%20user%20details%20from%20On-Premise%20AD%20to%20Azure%20AD%20but%20not%20the%20password%20.%20They%20don't%20want%20to%20sync%20the%20password%20for%20now%20and%20keep%20them%20segregated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20want%20to%20have%20few%20site%20with%20On-premise%20authentication%20and%20leaving%20the%20rest(as%20Teams%20are%20based%20on%20SharePoint%20online).%20So%2C%201.%20are%20there%20any%20solutions%20within%20Office365%20or%20third%20party%20AD%20authentication%20solutions.%202.%20Can%20the%20solution%20be%20applied%20to%20specific%20sites%20or%20does%20it%20have%20be%20all%20the%20sites%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2699363%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2699776%22%20slang%3D%22en-US%22%3ERe%3A%20SharePoint%20online%20single%20sign%20on%20with%20on-premise%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2699776%22%20slang%3D%22en-US%22%3EYou%20can%20sync%20the%20local%20AD%20with%20Azure%20AD%20without%20synchronizing%20passwords%20by%20deploying%20Azure%20AD%20Connect%20with%20PTA%20(Pass%20Through%20Authentication).%20In%20this%20way%2C%20passwords%20are%20always%20checked%20in%20local%20AD%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-pta%3FWT.mc_id%3DEM-MVP-4015732%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-pta%3FWT.mc_id%3DEM-MVP-4015732%3C%2FA%3E%3C%2FLINGO-BODY%3E
New Contributor

We are planning to implement intranet on SharePoint Online. Currently, the office 365 apps & SharePoint authentication is based on Azure AD which is office 365 email & password. However, we want to use on-Premise AD domain username and password for single sign-on. Our IT syncs only the user details from On-Premise AD to Azure AD but not the password . They don't want to sync the password for now and keep them segregated.

 

We want to have few site with On-premise authentication and leaving the rest(as Teams are based on SharePoint online). So, 1. are there any solutions within Office365 or third party AD authentication solutions. 2. Can the solution be applied to specific sites or does it have be all the sites?

 

Thanks.

3 Replies
You can sync the local AD with Azure AD without synchronizing passwords by deploying Azure AD Connect with PTA (Pass Through Authentication). In this way, passwords are always checked in local AD: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta?WT.mc_id=EM-MVP-40...

@Juan Carlos González Martín 

Thanks for the quick reply.

If the Azure AD connect with pass through is deployed then this would require users to authenticate all the cloud apps including SharePoint online with On-Premise AD. However, we are looking for some solution that only applies to SharePoint online and if possible only to limited number of sites so that the Teams SharePoint sites will not be effected. 

Hi,
I might be mistaken, but what you are looking for I'm pretty sure is not possible with SPO itself neither with a third party product. SPO relies on Azure AD as the rest of the services and solutions available in Microsoft 365