Forum Discussion
SSO for MS Outlook
Working with APM and Outlook OWA. I am able to get the logon page and pass creds but I want to do SSO and take the username/password and send to OWA but I am forwarded to OWA logon page.
Thoughts?
APM Logon Page > AD Auth > SSO Mapping > Allow
4 Replies
- Kevin_Stewart
Employee
You also need a forms SSO profile assigned to the access policy to consume the SSO mapping.
- Jason_19901
Nimbostratus
I have one of those
- Kevin_Stewart
Employee
First and foremost, I would highly recommend the Exchange iApp:
https://devcentral.f5.com/downloads/microsoft-exchange-2010-and-2013-iapp-template
The iApp will create a forms SSO that does the following (for Exchange 2010):
- Consumes the session.sso.token.last.username and session.sso.token.last.password from the SSO credential mapping agent
- Sets a start URI of: /owa/auth/logon.aspx?url=https://[Your OWA FQDN]/owa/&reason=0
- Form method: Post
- Form action: /owa/auth/owaauth.dll
- Form parameters: username and password
The SSO is then applied to the access policy. Is this more or less how you have it configured?
- Kevin_Stewart
Employee
First and foremost, I would highly recommend the Exchange iApp:
https://devcentral.f5.com/downloads/microsoft-exchange-2010-and-2013-iapp-template
The iApp will create a forms SSO that does the following (for Exchange 2010):
- Consumes the session.sso.token.last.username and session.sso.token.last.password from the SSO credential mapping agent
- Sets a start URI of: /owa/auth/logon.aspx?url=https://[Your OWA FQDN]/owa/&reason=0
- Form method: Post
- Form action: /owa/auth/owaauth.dll
- Form parameters: username and password
The SSO is then applied to the access policy. Is this more or less how you have it configured?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com