Skip to main content
Question

A guide to JSS Azure AD integration (LDAP + SSO)

  • October 26, 2017
  • 59 replies
  • 327 views

Show first post

59 replies

DBrowning
Forum|alt.badge.img+25
  • Esteemed Contributor
  • February 21, 2023

This is already the case.


What attribute do you have set for Username within the Azure Ldap mapping?  I would assume you are using the same when trying to auth.

 


anverhousseini
Forum|alt.badge.img+11
  • Valued Contributor
  • February 21, 2023

What attribute do you have set for Username within the Azure Ldap mapping?  I would assume you are using the same when trying to auth.

 


For username there is "userPrincipalName" which should be the mail address which I'm also using in the authentication.


DBrowning
Forum|alt.badge.img+25
  • Esteemed Contributor
  • February 21, 2023

For username there is "userPrincipalName" which should be the mail address which I'm also using in the authentication.


and to confirm if you do a test search for the email address it comes back with a user?


anverhousseini
Forum|alt.badge.img+11
  • Valued Contributor
  • February 21, 2023

and to confirm if you do a test search for the email address it comes back with a user?


Yes, this is working fine. We are already using the LDAP to fill the user and location inventory details with the SSO enrollment customization.


DBrowning
Forum|alt.badge.img+25
  • Esteemed Contributor
  • February 21, 2023

Yes, this is working fine. We are already using the LDAP to fill the user and location inventory details with the SSO enrollment customization.


Do you have password hash sync enabled in Azure?


anverhousseini
Forum|alt.badge.img+11
  • Valued Contributor
  • February 21, 2023

Do you have password hash sync enabled in Azure?


No, the customer has cloud only accounts, no hybrid environment.


DBrowning
Forum|alt.badge.img+25
  • Esteemed Contributor
  • February 21, 2023

No, the customer has cloud only accounts, no hybrid environment.


Still needs to be enabled from my understanding.  

Link for cloud-only user accounts.  


anverhousseini
Forum|alt.badge.img+11
  • Valued Contributor
  • February 21, 2023

Still needs to be enabled from my understanding.  

Link for cloud-only user accounts.  


Ok, I think that was the issue and also there was a setting called "LDAP Signing" or something. But it seems we need to reset the password for LDAP to work.


DBrowning
Forum|alt.badge.img+25
  • Esteemed Contributor
  • February 21, 2023

Ok, I think that was the issue and also there was a setting called "LDAP Signing" or something. But it seems we need to reset the password for LDAP to work.


Yeah once the sync is enabled, a password change is needed.