Forum Discussion

dkemper_258780's avatar
dkemper_258780
Icon for Nimbostratus rankNimbostratus
Oct 26, 2016

Office 365 Hybrid "thick" clients, totally replace ADFS (not just ADFS Proxy)

Goal: Hybrid Setup with Office 365, no p/w in cloud. Status. Set up (w/Big IP APM) and works great except for thick clients. Does the most recent iApp for ADFS or iApp for office 365 allow thick clients to authenticate, or is the iApp for ADFS at the point where it can replace ADFS (and not just ADFS proxy) ? Or if must be done manually, is there guidance for what info the big ip needs from O365 and what O365 is looking for from Big IP (and where to enter this config info)?

 

    • Niels_van_Sluis's avatar
      Niels_van_Sluis
      Icon for MVP rankMVP

      I'm also in te proces of setting up an BIG-IP to fully replace an ADFS server. And it seems to work fine (SSO). But we have an issue with the Office365 thick client. It prompts every time for 'license activation'. Then the user has to enter his e-mail address and the activation is completed. But since this is a VDI environment, the shared license information is not persistent.

      We tried to validate our configuration using the office365 SSO connectivity tester (https://testconnectivity.microsoft.com/) , but I don't know how reliable this test is. It fails with the following message:

       The Metadata Exchange URL in the domain registration isn't valid. URL:
      

      It is set within Azure (metadataExchangeUri) and points to the BIG-IP, but it seems the MEXURL isn't send by Azure. It shows .

      So any hints on this one? What can you tell me about the connectivity checker?

    • Michael_Koyfma1's avatar
      Michael_Koyfma1
      Icon for Cirrus rankCirrus

      Terry, I think we may be mixing up two topics here. The original topic of this thread was about replacing ADFS with APM - and that part works great for ADAL-enabled applications(as well as ActiveSync traffic). You are trying to deploy APM as a WAP/ADFS proxy, which is a bit of a different setup.

       

      Please open an a ticket with F5 support on it, and let me know the number via private message, and I will ensure it gets handled/routed properly. Currently, the deployment guide only covers SSO into ADFS using NTLM. Do you have a need to specifically support forms-based authentication method to ADFS. Our deployment guide exposes forms on the front-end and does NTLM SSO between APM and ADFS.

       

    • Terrence's avatar
      Terrence
      Icon for Nimbostratus rankNimbostratus

      I would really love to see the magic sauce that you are currently using, as any app that is using ADAL is not working for us, due to the multiple login screens.