Forum Discussion
Office 365 Hybrid "thick" clients, totally replace ADFS (not just ADFS Proxy)
Goal: Hybrid Setup with Office 365, no p/w in cloud. Status. Set up (w/Big IP APM) and works great except for thick clients. Does the most recent iApp for ADFS or iApp for office 365 allow thick clients to authenticate, or is the iApp for ADFS at the point where it can replace ADFS (and not just ADFS proxy) ? Or if must be done manually, is there guidance for what info the big ip needs from O365 and what O365 is looking for from Big IP (and where to enter this config info)?
- Lucas_Thompson_Historic F5 Account
Yes, this solution is fully supported using Office 365 thick client apps and APM as SAML IdP, so it's not necessary to transmit your AD user passwords to Microsoft.
This post has more information:
https://devcentral.f5.com/questions/office-365s-new-quotmodern-auth-quot
I'm also in te proces of setting up an BIG-IP to fully replace an ADFS server. And it seems to work fine (SSO). But we have an issue with the Office365 thick client. It prompts every time for 'license activation'. Then the user has to enter his e-mail address and the activation is completed. But since this is a VDI environment, the shared license information is not persistent.
We tried to validate our configuration using the office365 SSO connectivity tester (https://testconnectivity.microsoft.com/) , but I don't know how reliable this test is. It fails with the following message:
The Metadata Exchange URL in the domain registration isn't valid. URL:
It is set within Azure (metadataExchangeUri) and points to the BIG-IP, but it seems the MEXURL isn't send by Azure. It shows .
So any hints on this one? What can you tell me about the connectivity checker?
Terry, I think we may be mixing up two topics here. The original topic of this thread was about replacing ADFS with APM - and that part works great for ADAL-enabled applications(as well as ActiveSync traffic). You are trying to deploy APM as a WAP/ADFS proxy, which is a bit of a different setup.
Please open an a ticket with F5 support on it, and let me know the number via private message, and I will ensure it gets handled/routed properly. Currently, the deployment guide only covers SSO into ADFS using NTLM. Do you have a need to specifically support forms-based authentication method to ADFS. Our deployment guide exposes forms on the front-end and does NTLM SSO between APM and ADFS.
- TerrenceNimbostratus
I would really love to see the magic sauce that you are currently using, as any app that is using ADAL is not working for us, due to the multiple login screens.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com