Windows SfB 2016 authentication issues with MFA active (online only / current channel)

%3CLINGO-SUB%20id%3D%22lingo-sub-50474%22%20slang%3D%22en-US%22%3EWindows%20SfB%202016%20authentication%20issues%20with%20MFA%20active%20(online%20only%20%2F%20current%20channel)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-50474%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20so%20I%20could%20use%20some%20help%20with%20this%2C%20hopefully%20someone%20has%20the%20same%20scenario%20as%20us%20and%20could%20tell%20me%20if%20they%20have%20issues%20with%20Skype%20for%20Business%202016%20Windows%20Client%20as%20well.%20Here%20are%20the%20parameters%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EUsers%20federated%20with%20onPrem%20ADFS%20through%20AAD-Connect%3C%2FLI%3E%3CLI%3ESkype%20for%20Business%20Online%20only%20(no%20hybrid)%3C%2FLI%3E%3CLI%3EExchange%20Online%20Hybrid%20(through%20AAD-Connect)%3C%2FLI%3E%3CLI%3EADAL%20enabled%20for%20Skype%20Online%3CUL%3E%3CLI%3ESet-CsOAuthConfiguration%20-ClientAdalAuthOverride%20Allowed%3CUL%3E%3CLI%3Econfirmed%20this%20is%20set%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3EADAL%20enabled%20for%20Exchange%20Online%3CUL%3E%3CLI%3ESet-OrganizationConfig%20-OAuth2ClientProfileEnabled%3A%24true%3CUL%3E%3CLI%3Econfirmed%20this%20is%20set%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3EOffice%20365%20Pro%20Plus%20Setup%20is%20set%20to%20current%20channel%3CUL%3E%3CLI%3Ecurrent%20build%20is%3A%2016.0.7766.2060%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3EMFA%20enabled%20for%20my%20user%20account%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20issue%20is%20this%20annoying%20authentication%20window.%20It's%20in%20German%2C%20but%20I%20guess%20you%20know%20it%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20381px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F11505i9314C605B6F30D6B%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Image%20122.png%22%20title%3D%22Image%20122.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3ENormally%2C%20authentication%20works%20just%20fine%20when%20you%20boot%20up.%26nbsp%3BThis%20usually%20pops%20up%20when%20I%20undock%20my%20notebook%20(connection%20jumps%20to%20Corporate%20WiFi%20-%20802.1x).%26nbsp%3BThen%20there%20is%20just%20NO%20way%20to%20get%20rid%20of%20that%20window.%20I%20can%20try%20to%20enter%20my%20email%20(%3DUPN)%20and%20my%20password%20but%20this%20just%20pops%20up%20instantly.%3C%2FP%3E%3CP%3EI%20can%20try%20to%20shutdown%2C%20reboot%2C%20relog%2C%20logout%2C%20nothing%20will%20work.%20Next%20day%20or%20so%2C%20everything%20is%20fine%20after%20a%20clean%20boot.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20ideas%20why%20this%20popups%2C%20even%20though%20ADAL%20is%20enabled%20everywhere%3F%20The%20Skype%20client%20is%20the%20only%20one%20I'm%20having%20issues%20with.%20All%20other%20applications%20work%20just%20fine.%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20anything%20I%20have%20forgotten%20to%20change%2C%20possibly%20on%20the%20onPrem%20ADFS%20server%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-50474%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDesktop%20Client%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EFederation%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESign-in%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-63082%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20SfB%202016%20authentication%20issues%20with%20MFA%20active%20(online%20only%20%2F%20current%20channel)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-63082%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20ivan%2C%20%3CEM%3Ecreate%3C%2FEM%3Ea%20hive%2Fkey%20at%20(regedit)%20location%20mentioned%20in%20the%20article%20for%20SkB%202016%3C%2FP%3E%3CPRE%3EHKEY_CURRENT_USER%5CSoftware%5CPolicies%5CMicrosoft%5COffice%5C16.0%5CLync%3C%2FPRE%3E%3CP%3Eby%20right%20click%26gt%3BNew%26gt%3BKey%26gt%3B%20name%20it%20Lyn%20and%20then%20create%20new%20DWORD%20named%26nbsp%3BAllowAdalForNonLyncIndependentOfLync%2C%20right%20click%20modify%20and%20set%20value%20to%201.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-54661%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20SfB%202016%20authentication%20issues%20with%20MFA%20active%20(online%20only%20%2F%20current%20channel)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-54661%22%20slang%3D%22en-US%22%3E%3CP%3ESince%20the%20keys%20do%20not%20exists%2C%20I%20assumed%20they%20do%20not%20apply%20in%20our%20case.%20Also%20the%20affected%20client%20version%20is%20not%20listed%20for%20our%20case.%20There%20isn't%20even%20a%20%22lync%22%20hive%20under%20office%5C16.0%20for%20the%20Office%20365%20ProPlus%20Client.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-54639%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20SfB%202016%20authentication%20issues%20with%20MFA%20active%20(online%20only%20%2F%20current%20channel)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-54639%22%20slang%3D%22en-US%22%3EIvan%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20was%20under%20the%20same%20impression%2C%20but%20the%20keys%20did%20address%20the%20issue.%20I'd%20be%20curious%20to%20know%20if%20it%20did%20help%20your%20situation.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-53271%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20SfB%202016%20authentication%20issues%20with%20MFA%20active%20(online%20only%20%2F%20current%20channel)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-53271%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20just%20checked%20and%20I%20believe%20this%20should%20not%20apply%20to%20as%20we're%20not%20using%20any%20onPrem%20Skype%20Servers%20or%20have%20any%20pre%202016%20windows%20clients.%20We're%20fully%20online%20and%20on%20the%20latest%20client%20builds.%3C%2FP%3E%3CP%3EADAL%20should%20work%20out%20of%20the%20box%20for%20any%20Office%20365%20ProPlus%202016%20installations.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-52461%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20SfB%202016%20authentication%20issues%20with%20MFA%20active%20(online%20only%20%2F%20current%20channel)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-52461%22%20slang%3D%22en-US%22%3Ewill%20try%20it%20out%20tomorrow.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-52386%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20SfB%202016%20authentication%20issues%20with%20MFA%20active%20(online%20only%20%2F%20current%20channel)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-52386%22%20slang%3D%22en-US%22%3EApply%20the%20following%20regkey%20or%20in-band%20provisioning%20entry...%3CBR%20%2F%3E%3CBR%20%2F%3EWindows%20Registry%20Editor%20Version%205.00%3CBR%20%2F%3E%3CBR%20%2F%3E%5BHKEY_CURRENT_USER%5CSOFTWARE%5CPolicies%5CMicrosoft%5Coffice%5C16.0%5CLync%5D%3CBR%20%2F%3E%22AllowAdalForNonLyncIndependentOfLync%22%3Ddword%3A00000001%3CBR%20%2F%3E%3CBR%20%2F%3E%5BHKEY_CURRENT_USER%5CSOFTWARE%5CPolicies%5CMicrosoft%5Coffice%5C15.0%5CLync%5D%3CBR%20%2F%3E%22AllowAdalForNonLyncIndependentOfLync%22%3Ddword%3A00000001%3CBR%20%2F%3E%3CBR%20%2F%3Eor%3CBR%20%2F%3E%3CBR%20%2F%3E%24a%20%3D%20New-CsClientPolicyEntry%20-name%20AllowAdalForNonLyncIndependentOfLync%20-value%20%22True%22%3CBR%20%2F%3ESet-CsClientPolicy%20-Identity%20Global%20-PolicyEntry%20%40%7BAdd%3D%24a%7D%3CBR%20%2F%3E%3CBR%20%2F%3EKB3082803%20is%20the%20article%20you%20can%20reference.%3CBR%20%2F%3E%3CBR%20%2F%3Ei%20had%20similar%20issues%2C%20but%20the%20regkey%2Fin-band%20provision%20resolved%20the%20problem%20your%20are%20describing%20also.%3CBR%20%2F%3E%3CBR%20%2F%3ERegards%3CBR%20%2F%3E%3CBR%20%2F%3EChet%3C%2FLINGO-BODY%3E
Valued Contributor

Hi, so I could use some help with this, hopefully someone has the same scenario as us and could tell me if they have issues with Skype for Business 2016 Windows Client as well. Here are the parameters

 

  • Users federated with onPrem ADFS through AAD-Connect
  • Skype for Business Online only (no hybrid)
  • Exchange Online Hybrid (through AAD-Connect)
  • ADAL enabled for Skype Online
    • Set-CsOAuthConfiguration -ClientAdalAuthOverride Allowed
      • confirmed this is set
  • ADAL enabled for Exchange Online
    • Set-OrganizationConfig -OAuth2ClientProfileEnabled:$true
      • confirmed this is set
  • Office 365 Pro Plus Setup is set to current channel
    • current build is: 16.0.7766.2060
  • MFA enabled for my user account

 

The issue is this annoying authentication window. It's in German, but I guess you know it ;)

Image 122.png

Normally, authentication works just fine when you boot up. This usually pops up when I undock my notebook (connection jumps to Corporate WiFi - 802.1x). Then there is just NO way to get rid of that window. I can try to enter my email (=UPN) and my password but this just pops up instantly.

I can try to shutdown, reboot, relog, logout, nothing will work. Next day or so, everything is fine after a clean boot.

 

Any ideas why this popups, even though ADAL is enabled everywhere? The Skype client is the only one I'm having issues with. All other applications work just fine. 

Is there anything I have forgotten to change, possibly on the onPrem ADFS server?

 

6 Replies
Apply the following regkey or in-band provisioning entry...

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\office\16.0\Lync]
"AllowAdalForNonLyncIndependentOfLync"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\office\15.0\Lync]
"AllowAdalForNonLyncIndependentOfLync"=dword:00000001

or

$a = New-CsClientPolicyEntry -name AllowAdalForNonLyncIndependentOfLync -value "True"
Set-CsClientPolicy -Identity Global -PolicyEntry @{Add=$a}

KB3082803 is the article you can reference.

i had similar issues, but the regkey/in-band provision resolved the problem your are describing also.

Regards

Chet

I've just checked and I believe this should not apply to as we're not using any onPrem Skype Servers or have any pre 2016 windows clients. We're fully online and on the latest client builds.

ADAL should work out of the box for any Office 365 ProPlus 2016 installations.

Ivan,

I was under the same impression, but the keys did address the issue. I'd be curious to know if it did help your situation.

Since the keys do not exists, I assumed they do not apply in our case. Also the affected client version is not listed for our case. There isn't even a "lync" hive under office\16.0 for the Office 365 ProPlus Client.

Hi ivan, create a hive/key at (regedit) location mentioned in the article for SkB 2016

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Lync

by right click>New>Key> name it Lyn and then create new DWORD named AllowAdalForNonLyncIndependentOfLync, right click modify and set value to 1.