
y659d (y659d) asked a question.
When I turn on the WS-Federation with Office 365 will my users have to resign-in to Outlook on PC/mobile? Will they even notice anything? I am not going to implement MFA right away but roll that out slowly to all users. We are already using AAD Connect so their AD password and O365 password already match.

Thanks for contacting the Okta Community.
Clients sessions like Outlook, are controlled by an access token and a session token issued by o365, the lifespan of these tokens are usually 90days. this sessions are not controlled by Okta. So when you enable o365 federation, users logged to outlook wont be prompted for credentials until their token expires, after that they will be prompted for the Okta login.