【Single Sign-On and Multi-Factor Authentication for Office 365 with TrustLogin】
You can use Microsoft 365 SAML Automatic Configuration independently of the Microsoft 365 (Office 365) Integration.
However, since the Immut
Note: ImmutableID is set by syncing Active Directory and Microsoft Entra ID via Microsoft Entra Connect.
If you are not planning to use this configuration, please consider using Microsoft 365 (Office 365) Integration instead.
Note: Signing in to Windows OS does not support SAML authentication by default.
To support it, you need to enable Web Sign-in as a sign-in option for Windows OS.
https://learn.microsoft.com/en-us/windows/security/identity-protection/web-sign-in/?tabs=intune
Please note that even if you enable the Web Sign-in option described above, if you are using TrustLogin's certificate authentication feature, sign-in will fail with an error because the OS certificate cannot be referenced before signing in to Windows OS.
Note: To use this feature, you need to subscribe to the TrustLogin Pro Plan or the SCIM IDP Integration option.
For pricing, please see here
Note: The SAML-SSO of Microsoft 365 (Office 365) Integration and Microsoft 365 (SAML Automatic Configuration) are the same feature, and since both act on the same Microsoft Entra ID feature and interfere with each other, using them in parallel is not recommended.
Setup Instructions
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "Microsoft 365 (SAML Automatic Configuration)."
-
Click "Register."
-
Configure the SAML settings. From the app settings screen, select "Enable SSO (SAML)."
-
Select "Next."
-
Log in with the Microsoft account you want to link via SAML.
-
Click "Accept."
-
Check "Consent on behalf of your organization" and click "Accept."
-
Select the domain for which you want to enable SSO (SAML) integration and click "Complete."
-
SAML-SSO is now enabled, and the selected domain is displayed in the "SSO Domain" field.
-
Add members. From the app management screen, select "Add Member," then select and register the target domain users who have already been linked with Entra ID.
-
The app icon will appear on the My Page of users to whom the app has been assigned.
-
Clicking the app icon takes you to the Microsoft 365 screen.