Microsoft SSO plug-in blocking Microsoft Teams sign-in

RolindaS
New Contributor II

We have the Microsoft SSO plug-in Configure and deployed to all managed clients, upon initial sign-in or after sometime, signing into Microsoft Teams is blocked and end users are unable to sign-in to Teams, when we unstop the configuration profile from the affected devices users are then able to sign-into Teams, please note the SSO plug-in works with all other MS and 3rd Party apps that use Entra Authentication.

Please advise if anyone has this issue and if there are any solutions. Screenshot 2024-05-21 at 4.58.18 PM.png 
Teams sign-in gets stuck here when selecting your account nothings happens no errors, no prompts.
Screenshot 2024-05-22 at 20.59.07.pngScreenshot 2024-05-22 at 20.59.33.png

11 REPLIES 11

LucasZhang
New Contributor

Dont use the plug in then

RolindaS
New Contributor II

That's not very helpful.

scottlep
Contributor II

We have the same issue with a small percent of our users. It happens only with New Teams. In most cases users have been successfully signing-in for an extended period then suddenly cannot get past the "Welcome to Teams" window. All other MS apps work as expected for SSO. We have tried all standard troubleshooting steps. uninstall/reinstall, delete caches related to Teams/Office, clear Keychain items related to Teams/Office. It isn't related to a certain Teams or macOS version as we have seen the issue on various versions of both. We have even complete wiped a Mac, re-provisioned and the issue returned for that user a short time later. We have had a ticket open for weeks with MS and have gotten nowhere as usual. In some cases the user can randomly start using Teams as expected a few days/weeks after the issue. 

RolindaS
New Contributor II

Thanks for your response, have you received any feedback from Microsoft? 

 

andrew_nicholas
Valued Contributor

Check this thread in the macadmins Slack: https://macadmins.slack.com/archives/C70CN1UUC/p1714582854943809.

daniel_behan
Contributor III

This one has been working for me.  I have a few more URLs than you do.Screenshot 2024-05-31 at 3.51.34 PM.png

elsmith
Contributor II

We recently deployed the SSO plug-in, as well. At the time, we didn't realize it was related to Teams, specifically, but we did find something that worked to fix it (or band-aid fix it, maybe... too early to tell!). What we do see (not sure if this is the same thing y'all are seeing) is that EVERY application that uses MS SSO starts prompting like this:

image-2024-5-8_11-17-45.png

How we've fixed it:

  1. Close Teams if it's open
  2. Open the Keychain Access application and search for Microsoft
  3. Delete anything with "certauth.login.microsoftonline.com" in it (there's always one, may be two)
  4. Delete anything with "accesstoken" in it (there's usually a BUNCH of these)
  5. Close Keychain Access
  6. Retry Teams

This has worked in about 95% of the "broken" folks we've had. Of course, it requires a call to the helpdesk which we're trying to avoid, so hopefully MS can fix this sooner rather than later.....

We've also seen other issues with the certificates in Firefox... and those are fixed in a similar fashion (but inside the app):

  1. Open Firefox
  2. Open settings
  3. Search for certificates and click "View Certificates"
  4. Click on Authentication Decisions
  5. Delete the certauth.login.microsoftonline certificates (we usually see 2 or 3)
  6. Click OK
  7. Close Firefox

 

Shailee_Shah
New Contributor II

Have you found a solid working solution for this that fixes the root cause? 

spalladino
New Contributor III

I, too, am interested in an actual solution to this problem. My users liek having the SSO config profile as it lessons the login windows in the environment but not being able to login to Teams or outlook is a issue and it seems it does nto affect everyone just a random subset of users usually at time of password change.  

dubel
New Contributor III

Has anyone found any solutions to this issue?

Shailee_Shah
New Contributor II

In addition to the SSO policy check with your Network Security team to ensure the following URL are NOT being inspected. 

  • app-site-association.networking.apple
  • app-site-association.cdn-apple.com

If you go to the following link and scroll down to the Validate Networking Configuration on macOS device you will see it is mandate to not TLS inspect the domains above, I recently found our environment was inspecting these domains which was causing inconsistent connection. We have since bypassed them and are seeing a better performance.