This page introduces frequently asked questions about the Microsoft 365 (Office 365) integration feature.
If you have any questions, please be sure to read through it.
If this does not resolve your issue, please feel free to contact us.
Frequently Asked Questions
Q 1) I do not have integration (federation) permissions.
A 1) You must be logged in with administrator privileges on both Microsoft 365 (Office 365) and TrustLogin.
Q 2) The target domain does not have the "Enable automatic SSO (SAML) configuration" setting.
A 2) Please check the following points.
- Are you using onmicrosoft.com? SSO cannot be enabled for onmicrosoft.com.
- Is the domain set as the default domain (primary domain)? SSO cannot be enabled for the default domain. Please set a different domain as the default domain.
Q 3) Can I integrate (federate) with multiple domain names at the same time?
A 3) Yes, this is possible. Please refer to the manuals below according to your Microsoft 365 (Office 365) usage situation.
Note: Enabling federation for a parent domain will enable federation for all of its child domains as well, so please be careful.
Q 4) If I am already using Microsoft 365 (Office 365), what changes for users before and after integration (federation)?
A 4) You will no longer be able to log in with the Microsoft 365 (Office 365) password you used before integration (federation). After integration (federation), logging in to Microsoft 365 (Office 365) will switch to SAML authentication via TrustLogin.
■ If you are currently using another identity provider:
After integration (federation), the identity provider for Microsoft 365 (Office 365) will switch to TrustLogin.
Since you will log in to Microsoft 365 (Office 365) via TrustLogin, if members are unable to log in to TrustLogin, Microsoft 365 (Office 365) will become unavailable.
Q 5) Will a group integrated (federated) from TrustLogin also be integrated as a group on the Microsoft 365 (Office 365) side?
A 5) Even if you integrate a group on the TrustLogin side, a group will not be created in Microsoft 365 (Office 365). The users within the integrated group are synced instead.
Q 6) If I remove a member from TrustLogin's Microsoft 365 (Office 365) integration, will the user be deleted on the Microsoft 365 (Office 365) side?
A 6) You can choose in the settings whether to delete the user or leave them active.
(!) If you do not want members to be deleted from Microsoft 365 (Office 365) at the same time as unlinking, please check in advance on the Microsoft 365 (Office 365) integration settings screen below whether the "Delete user in Office 365 after unlinking" toggle is set to "Off." If it is set to "On," the Microsoft 365 (Office 365) user will also be deleted.
Note: Deleted users can be restored within 30 days of deletion. After 30 days have passed, any documents the user owned will also be deleted.
The default setting is "Off."
Q 7) The Microsoft 365 (Office 365) license selected when integrating a user from TrustLogin is not being assigned to the user.
A 7) If the number of available Microsoft 365 (Office 365) licenses is 0, the license cannot be assigned due to insufficient licenses. The user will be assigned a license labeled "NO_LICENSE."
Q 8) When logging in from a desktop app such as Outlook, the TrustLogin login screen appears and then immediately disappears, repeating this behavior.
A 8) Communication with TrustLogin may be blocked by a security setting. Please add "https://*.trustlogin.com" to Internet Options - Security - Trusted Sites - Sites, and check whether you are then able to log in.
Q 9) Enabling the client authentication option in the Outlook app for iOS causes login to fail.
A 9) The Microsoft Authenticator app is required. Please install it on your iOS device.
Q 10) I assigned a user to both the main domain (example.com) and a subdomain (sub.example.com), but login fails on one of them.
A 10) If the main domain and subdomain share the same SSO configuration, the user will only be able to log in on one of the domains. Please assign the user to only one of the domains.
Q 11) Even after turning off "Enable automatic SSO (SAML) configuration" in the Office 365 integration option, SSO does not become disabled.
A 11) Depending on the timing, it may take some time for the setting change to take effect. Please wait about 30 minutes and check again.
Q 12) The license name shown in the Office 365 integration option is different from the actual product name under contract.
A 12) TrustLogin displays the license name obtained via the API on the Admin Page. For the mapping to actual product names, please refer to Microsoft's documentation.
Q 13) Can I change the display order of "first name, last name" for the "display name" on the Microsoft 365 (Office 365) side?
A 13) Yes. You can change the display order of the display name in Office 365 from the TrustLogin settings screen.
Within the Microsoft 365 (Office 365) integration settings screen below,
you can configure this using the "Set the Office 365 display name order to last name, first name" toggle.
Toggle ON: The display name on the Office 365 side becomes "Last Name, First Name"
OFF: The display name on the Office 365 side becomes "First Name, Last Name"
Note: The default is ON (Last Name, First Name).
Q 14) Users provisioned through TrustLogin's Microsoft 365 (Office 365) integration
are frequently prompted to sign in.
A 14) Please set the "LastPasswordChangeTimestamp" and
"StsRefreshTokensValidFrom" attributes for the Azure AD user using a PowerShell command. For details, please see the page below.
When you are frequently prompted to sign in with Microsoft 365 (Office 365)
Q 15) A license that was previously assigned on the Microsoft 365 (Office 365) side gets removed.
A 15) Licenses set manually are overwritten by the automatic process. Even if you manually change user attributes or license assignments in the Microsoft 365 admin center, the Microsoft 365 (Office 365) integration option treats the information configured in TrustLogin as the source of truth, so it will be overwritten during synchronization. When changing user attributes or license assignments, please make the change from the TrustLogin Admin Page.
Please refer to the table below for the behavior when assigning licenses.
| Microsoft 365 License Status | TrustLogin Integration License Status | Result After Integration |
| None | Business Premium | BusinessPremium |
| Business Premium | Business Premium | BusinessPremium |
| BusinessStandard | Business Premium | BusinessPremium |
| Business Premium | NO LICENCE | None |
Q 16) I want to prevent a SAML app from being displayed on My Page.
A 16) here, you can configure the SAML app to be hidden.