<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007dCpNDCA0Okta Classic EngineOkta Integration NetworkAnswered2022-05-06T23:26:08.000Z2022-05-05T20:24:46.000Z2022-05-06T23:26:07.000Z

CliftonY.46624 (Customer) asked a question.

SSO to on-premise domain-joined resources on AzureAD joined device

I'm reposting a question for a post which is closed but apparently no answer on the question anyway.

https://support.okta.com/help/s/question/0D51Y00007qkKLzSAM/sso-to-onpremise-domainjoined-resources-on-azuread-joined-device?language=en_US

 

We're migrating our devices to AzureAD joined (No Hybrid AAD join). We have on-premise resources include a file share and numerous of Windows-Integrated-Authentication web services that need to be seamlessly (SSO/without password) accessed.

 

According to Microsoft documents (https://docs.microsoft.com/en-us/azure/active-directory/devices/azuread-join-sso), AzureADConnect provides seamless single sign-on to on premise resources via kerberos TGT tickets when there is a domain controller in sight.

As part of the synchronization process, Azure AD Connect synchronizes on-premises user information to Azure AD. When a user signs in to an Azure AD joined device in a hybrid environment:

  1. Azure AD sends the name of the on-premises domain the user is a member of back to the device.
  2. The local security authority (LSA) service enables Kerberos authentication on the device.

 

Currently Okta manage all of accounts (people). On-prem AD is integrated with Okta thru Directory Integration (Okta AD Agent) and is a profile source in Okta. Office 365 is integrated thru WS-FED/SAML thru "User Sync" with password sync enabled. Okta is the IDP for all of the SSO/SAML App include Office 365.

 

Does any one know if there is a way to make the client (Azure AD Joined Device) able to access the on-perm resources w/o password prompt.


This question is closed.
Loading
SSO to on-premise domain-joined resources on AzureAD joined device