Okta Blocks Authentications When Integrating Office 365 With Microsoft Intune
Last Updated:
Overview
When integrating Office 365 with Okta and Microsoft Intune, Okta blocks authentication attempts because the Windows login screen uses a legacy authentication flow that the default Okta Application Sign-On Policy denies. Administrators must configure a new or existing sign-on policy to allow legacy authentication. During this integration, Okta denies the authentication attempts, and the System Log displays one or both of the following events:
DisplayMessage - Deny user access due to app sign on policy
EventType - application.policy.sign_on.deny_access
Applies To
- Okta Classic Engine
- Okta Identity Engine
- Application Sign-On Policy
- Microsoft Intune
- Office 365
Cause
Authentication from the Windows login screen using the password factor is a legacy authentication flow against Okta.
Solution
What steps configure the Okta Application Sign-On Policy to allow legacy authentication in Okta Identity Engine?
The default Okta Application Sign-On Policy blocks legacy authentication, so administrators must configure an App sign-on policy to allow legacy authentication by navigating to the Office 365 application and modifying the policy rules.
- Navigate to the Office 365 application within the Okta Admin Console.
- Select Sign-on.
- Scroll all the way down to User authentication.
- Select View policy details.
- Select the Edit (pencil) icon to modify an existing rule, or select Add Rule to add a new rule.
- Scroll to the AND Client is field and select One of the following clients, and select Exchange ActiveSync/Legacy Auth from the drop-down.
- In the THEN Access is section, set the value to Allowed after successful authentication.
- Select Save.
What steps configure the Okta Application Sign-On Policy to allow legacy authentication in Okta Classic Engine?
Navigate to the Office 365 application in the Okta Admin Console and modify the application sign-on policy rules to allow legacy authentication.
- Navigate to the Office 365 application within the Okta Admin Console.
- Select Sign-on.
- Scroll to the Sign On Policy section.
- Select the Edit (pencil) icon to modify an existing rule, or select Add Rule to add a new rule.
- Scroll to the CLIENT section of the rule configuration prompt and select the Exchange ActiveSync/Legacy Auth checkbox.
- In the ACCESS section, set the value to When all the conditions above are met, sign on to this application is: to Allowed from the dropdown menu.
- Select Save.
