<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Blocks Authentications When Integrating Office 365 With Microsoft Intune

Okta Classic Engine
Okta Identity Engine
Single Sign-On
All Engines

Overview

When integrating Office 365 with Okta and Microsoft Intune, Okta blocks authentication attempts because the Windows login screen uses a legacy authentication flow that the default Okta Application Sign-On Policy denies. Administrators must configure a new or existing sign-on policy to allow legacy authentication. During this integration, Okta denies the authentication attempts, and the System Log displays one or both of the following events:

 

DisplayMessage - Deny user access due to app sign on policy
EventType - application.policy.sign_on.deny_access

 

Applies To

  • Okta Classic Engine
  • Okta Identity Engine
  • Application Sign-On Policy
  • Microsoft Intune
  • Office 365

Cause

Authentication from the Windows login screen using the password factor is a legacy authentication flow against Okta.

Solution

What steps configure the Okta Application Sign-On Policy to allow legacy authentication in Okta Identity Engine?

The default Okta Application Sign-On Policy blocks legacy authentication, so administrators must configure an App sign-on policy to allow legacy authentication by navigating to the Office 365 application and modifying the policy rules.

  1. Navigate to the Office 365 application within the Okta Admin Console.
  2. Select Sign-on.
  3. Scroll all the way down to User authentication.
  4. Select View policy details.
  5. Select the Edit (pencil) icon to modify an existing rule, or select Add Rule to add a new rule.
  6. Scroll to the AND Client is field and select One of the following clients, and select Exchange ActiveSync/Legacy Auth from the drop-down.
  7. In the THEN Access is section, set the value to Allowed after successful authentication.
  8. Select Save.

Legacy Auth Rule

 

What steps configure the Okta Application Sign-On Policy to allow legacy authentication in Okta Classic Engine?

Navigate to the Office 365 application in the Okta Admin Console and modify the application sign-on policy rules to allow legacy authentication.

  1. Navigate to the Office 365 application within the Okta Admin Console.
  2. Select Sign-on.
  3. Scroll to the Sign On Policy section.
  4. Select the Edit (pencil) icon to modify an existing rule, or select Add Rule to add a new rule.
  5. Scroll to the CLIENT section of the rule configuration prompt and select the Exchange ActiveSync/Legacy Auth checkbox.
  6. In the ACCESS section, set the value to When all the conditions above are met, sign on to this application is: to Allowed from the dropdown menu.
  7. Select Save.

Okta classic ASOP O365

Loading
Okta Blocks Authentications When Integrating Office 365 With Microsoft Intune | Okta Support