<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006ODm4gSADOkta Classic EngineOkta Integration NetworkAnswered2025-02-02T09:02:02.000Z2019-06-27T16:22:54.000Z2019-07-01T13:57:06.000Z

me6vm (me6vm) asked a question.

End User experience when enabling Office 365 WS-Federation

Hello All,

 

My company would like to move from SWA to WS-Federation. I am looking to see if any can describe the end user experience when this happens.

 

  • Do all users need to login back in? Mobile apps and thick clients as well?
  • Will their original O365 password be overridden?

 

Hoping to gather some details that I can communicate to our users.

 

Thank you,

Netti

 


  • Thank you for reaching out to Okta Support regarding your inquiry, my name is Mihail.

     

     

     

    Authentication flow on the high level should be similar to SAML. The WS-Federation uses a Request Security Token(RST) and Request Security Token Response(RSTR)). When you access the web application it sends the query in the Request Security token to the Identity Provider. The identity provider will verify the RST and the identity of the user it will send a Request Security Token response back to the application.

     

     

     

    For more details regarding this transition from SWA to WS-Federation, please, look below:

    https://help.okta.com/en/prod/Content/Topics/Apps/Apps_Moving_Microsoft.htm

     

     

     

    If are you planning to use the WS-Federation Template app. You can take a look at our resources to configure the template WS-Federation application.

    https://support.okta.com/help/s/article/Configuring-the-Okta-Template-WS-Federation-Application-1608603212  

     

     

     

    If you are planning to WS-Fed Office 365 the below link is a good place to start.

    https://support.okta.com/help/s/article/Configuring-WS-Fed

     

     

     

    If you require more concrete information, please, feel free to open a ticket with us and we will be there to help you.

    Expand Post
  • HI John,

     

    You users won't see a change in their experience until the Microsoft session timeout expires. At that time, they will be redirected to Okta for login. If they are on the network and you have IWA enabled (an no MFA on network) they won't notice anything. If off the network/no IWA, they will get the Okta sign in and will need to use their Okta creds (I assume both Okta & O365 are federated with AD so it's the same username/pwd for them - if not, they will need to use their Okta password. ) There are two key things that tend to jump out and get you..... those darn session timeouts at Microsoft... as long as that session cookie is active, the user will never go back to Okta to authenticate. https://docs.microsoft.com/en-us/office365/enterprise/session-timeouts

    The other is to watch for accounts that are in use for O365 but not in Okta.... things like receptionist@ or security guard@, skype phones, and conference room ipads... all those things need to log in to O365 and if the O365 login suffix matches the federated email suffix, then those users will be redirected to Okta. If you can, I recommend registering a test domain to your O365 tenant and practicing the federation with that. It will let you get comfortable with little risk.

     

    Expand Post
This question is closed.
Loading
End User experience when enabling Office 365 WS-Federation