
me6vm (me6vm) asked a question.
Hello All,
My company would like to move from SWA to WS-Federation. I am looking to see if any can describe the end user experience when this happens.
- Do all users need to login back in? Mobile apps and thick clients as well?
- Will their original O365 password be overridden?
Hoping to gather some details that I can communicate to our users.
Thank you,
Netti

Thank you for reaching out to Okta Support regarding your inquiry, my name is Mihail.
Authentication flow on the high level should be similar to SAML. The WS-Federation uses a Request Security Token(RST) and Request Security Token Response(RSTR)). When you access the web application it sends the query in the Request Security token to the Identity Provider. The identity provider will verify the RST and the identity of the user it will send a Request Security Token response back to the application.
For more details regarding this transition from SWA to WS-Federation, please, look below:
https://help.okta.com/en/prod/Content/Topics/Apps/Apps_Moving_Microsoft.htm
If are you planning to use the WS-Federation Template app. You can take a look at our resources to configure the template WS-Federation application.
https://support.okta.com/help/s/article/Configuring-the-Okta-Template-WS-Federation-Application-1608603212
If you are planning to WS-Fed Office 365 the below link is a good place to start.
https://support.okta.com/help/s/article/Configuring-WS-Fed
If you require more concrete information, please, feel free to open a ticket with us and we will be there to help you.
HI John,
You users won't see a change in their experience until the Microsoft session timeout expires. At that time, they will be redirected to Okta for login. If they are on the network and you have IWA enabled (an no MFA on network) they won't notice anything. If off the network/no IWA, they will get the Okta sign in and will need to use their Okta creds (I assume both Okta & O365 are federated with AD so it's the same username/pwd for them - if not, they will need to use their Okta password. ) There are two key things that tend to jump out and get you..... those darn session timeouts at Microsoft... as long as that session cookie is active, the user will never go back to Okta to authenticate. https://docs.microsoft.com/en-us/office365/enterprise/session-timeouts
The other is to watch for accounts that are in use for O365 but not in Okta.... things like receptionist@ or security guard@, skype phones, and conference room ipads... all those things need to log in to O365 and if the O365 login suffix matches the federated email suffix, then those users will be redirected to Okta. If you can, I recommend registering a test domain to your O365 tenant and practicing the federation with that. It will let you get comfortable with little risk.