Setup Procedure Pattern 3: "New to Microsoft 365 (Office 365), Already Using TrustLogin"

The "Microsoft 365 (Office 365) Integration" feature
enables user information synchronization, license assignment, and SAML authentication for Microsoft 365 (Office 365), using TrustLogin as the source of information.

If you are already using TrustLogin and are newly introducing Microsoft 365 (Office 365), please proceed with the setup using the steps below.

Note: Do not manually assign licenses from the Microsoft 365 admin center. They may be unintentionally removed by automatic control.

Note: For details, click here to check.

Note: After the integration is configured, within the federated domain on the Microsoft 365 (Office 365) side,
you will no longer be able to create new users.

Note: We have confirmed an issue where users provisioned through TrustLogin's Microsoft 365 (Office 365) integration
are frequently prompted to sign in.
For information on how to resolve this, please click here.

Note: When integrating users via a "Group," we have confirmed an issue where the Office 365 user cannot be deleted even if "Delete user in Office 365 after unlinking: ON" is set. If you are integrating via a group, please delete the user manually on the Office 365 side.


Table of Contents:

Setup Procedure

 1. Account Integration Settings
 2. Adding Members
 3. SAML Integration Settings
Refresh Integration
Frequently Asked Questions


Setup Procedure

1. Account Integration Settings

Preliminary Check

On the Microsoft 365 (Office 365) side, regarding the federation status of Azure Active Directory (hereinafter AD),
please check the following:

  1. ○○.onmicrosoft.com and the primary domain cannot be federated (integrated).
    Please confirm that the domain you want to integrate is not the primary domain.
  2. The domain to be federated (integrated) must not already be federated.
    Please confirm that the "Status" shows "Verified."

    01_1.png

Setup Method

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button for "Office 365 Integration."

    02.png
  2. Click "Set up Office 365." (You will be redirected to Microsoft 365 (Office 365).)

    03.png
  3. Log in to Microsoft 365 (Office 365) with an administrator account.
    Note: We recommend using an administrator account with a UPN that includes xxx.onmicrosoft.com for the 365 integration settings.
    04__1_.png
  4. Click "Accept" to grant TrustLogin access permission to Microsoft 365 (Office 365).

    05.png
  5. The account selection screen will appear again. Select the account you want to federate.

    04.png
  6. Check "Consent on behalf of your organization" and click Accept.

    06.png
  7. When the list of domain names registered in Microsoft 365 (Office 365) is displayed, setup is complete.

2. Adding Members

Preliminary Check

Note: Before integration, the TrustLogin member ID must match the Microsoft 365 (Office 365) username.

Integration Behavior List

Microsoft 365 (Office 365)
User
TrustLogin User Integration Behavior
Account already exists
aaa@example.com

Microsoft 365 (Office 365) user and username

match
aaa@example.com

Integration is completed, and the TrustLogin account information is synced to Microsoft 365 (Office 365).
aaa@example.com
Account already exists
aaa@example.com

Microsoft 365 (Office 365) user and username

do not match
aac@example.com

Because integration with Microsoft 365 (Office 365) does not occur, the Microsoft 365 (Office 365) user (aaa@example.com) remains as is, but is not managed by TrustLogin.

In addition, a new Microsoft 365 (Office 365) user is created using the TrustLogin username (aac@example.com).

Account does not exist

-

New account created

abc@example.com

Integration with Microsoft 365 (Office 365) occurs, and a new Microsoft 365 (Office 365) user (abc@example.com) is created.

If the domain names of Microsoft 365 (Office 365) and TrustLogin differ, the following behavior occurs.

Microsoft 365 (Office 365)
User
TrustLogin User Integration Behavior

Already in the "example.com" domain,

an account exists
aaa@example.com

The Microsoft 365 (Office 365) domain name and the domain name of the TrustLogin username do not match

aaa@forexample.com

Integration is completed, and the TrustLogin account information is synced to Microsoft 365 (Office 365).
aaa@example.com

Already in the "example.com" domain,

an account exists
aaa@example.com

The Microsoft 365 (Office 365) domain name and the domain name of the TrustLogin username do not match, and the part before the "@" also does not match
bbb@forexample.com

Because integration with Microsoft 365 (Office 365) does not occur, the Microsoft 365 (Office 365) user (aaa@example.com) remains as is, but is not managed by TrustLogin.

In addition, a new Microsoft 365 (Office 365) user is created using the TrustLogin username (bbb@example.com).

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button for "Office 365 Integration."

    01.png
  2. Members are assigned per "domain name" and "license."
    Note: The same member can be assigned to multiple domain names and multiple licenses. (Microsoft 365 (Office 365) licenses will be consumed accordingly.)
    Note: The Microsoft 365 (Office 365) user "user_name@o365-domain.com" is created from the user_name portion of the TrustLogin member name "user_name@tl-domain.com" combined with the assigned Microsoft 365 (Office 365) domain "o365-domain.com."

    Click the target domain name.

    office365-2.png
  3. A list of licenses associated with the target domain name will be displayed. Click the license you want to assign.

    office365-3.png
  4. Click "Add Member" displayed in the upper right. (You can also use "Add Group" to assign an entire group.)
    Note: When integrating users via a "Group," we have confirmed an issue where the Office 365 user cannot be deleted even if "Delete user in Office 365 after unlinking: ON" is set. If you are integrating via a group, please delete the user manually on the Office 365 side.



    office365-4.png

  5. Check the members you want to add, and click the "Register" button.

    03.png
  6. Confirm that the members have been added.

    04.png
  7. Microsoft 365 admin center will provision the member.

    For the member information sync field mapping table used when integrating TrustLogin with Microsoft 365 (Office 365), please see here.
    30.png


  8. Azure Active Directory portal will provision and sync the member.

    31.png


  9. Confirm that the "Office 365" app has been added to the "My Page" of the added member.

    Note: The Office 365 SAML app icon appears on the My Page of assigned users only when SAML integration is ON for the target domain name.

    12.png

  10. Clicking the app logs you in via SAML authentication.

    13.png

3. SAML Integration Settings

Important Notes

SAML integration settings are enabled on a per-domain basis.
Note: SAML authentication can be used with web browsers, desktop apps such as Outlook, and mobile apps.
Note: There have been reports of users integrated with Microsoft 365 (Office 365) being unable to log in to devices joined to Azure AD. Please note that we do not support using Microsoft 365 (Office 365) integrated users for Windows sign-in on devices joined to Azure AD.


Note: This can only be configured for domains other than the primary domain and onmicrosoft.com. For domain names where this cannot be configured, the "Edit" button and the "Enable automatic SSO (SAML) configuration" option will not be displayed, as shown in the image below.

office365-SAML2.png

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button for "Office 365 Integration."

    02.png
  2. Click the domain name for SAML integration.

    office365-2.png
  3. Click the "Edit" button.

    office365-SAML1.png
  4. Click the toggle next to "Enable automatic SSO (SAML) configuration" to turn it green ("ON"), and then click the "Save" button.

    When turning ON "Enable automatic SSO (SAML) configuration," you now need to select the "SSO source domain." This selects the domain that is the source of the SSO (SAML) configuration used by the target domain. If the target domain is a subdomain, specify the parent domain. If the target domain is itself the SSO source, the SSO target and source will be the same domain. By default, the same domain is specified for both the SSO target and source.
    Note: If a TrustLogin user is assigned to both a parent domain and a subdomain, SSO will only work for the domain that was assigned later.

    office365-SAML3.png
  5. An image will be displayed until the configuration is complete, so please wait a moment.

    office365-SAML4.png
  6. When the image display ends and the "Edit" button appears, SAML integration is complete.


    office365-SAML5.png

    Note: If you do not want the SAML app icon to appear on My Page, you can hide it by disabling the checkbox option below.

Refresh Integration

If a domain is added or removed on the Microsoft 365 (Office 365) side, you can refresh the integration to retrieve the latest domain information. This can also be used to refresh the integration when the token has expired.

  1. Click "Refresh Integration."
    koushin01.png
  2. Click "Yes" to grant consent as the Office 365 administrator.
    koushin02.png

  3. Perform the same steps as step 3 onward in the "Account Integration Settings" setup method.

Frequently Asked Questions

There is also a page that compiles frequently asked questions about Microsoft 365 (Office 365) integration. Please check it as needed.

Frequently Asked Questions and Answers about the Microsoft 365 (Office 365) Integration Feature

Setup Procedure Pattern 3: "New to Microsoft 365 (Office 365), Already Using TrustLogin"

The "Microsoft 365 (Office 365) Integration" feature
enables user information synchronization, license assignment, and SAML authentication for Microsoft 365 (Office 365), using TrustLogin as the source of information.

If you are already using TrustLogin and are newly introducing Microsoft 365 (Office 365), please proceed with the setup using the steps below.

Note: Do not manually assign licenses from the Microsoft 365 admin center. They may be unintentionally removed by automatic control.

Note: For details, click here to check.

Note: After the integration is configured, within the federated domain on the Microsoft 365 (Office 365) side,
you will no longer be able to create new users.

Note: We have confirmed an issue where users provisioned through TrustLogin's Microsoft 365 (Office 365) integration
are frequently prompted to sign in.
For information on how to resolve this, please click here.

Note: When integrating users via a "Group," we have confirmed an issue where the Office 365 user cannot be deleted even if "Delete user in Office 365 after unlinking: ON" is set. If you are integrating via a group, please delete the user manually on the Office 365 side.


Table of Contents:

Setup Procedure

 1. Account Integration Settings
 2. Adding Members
 3. SAML Integration Settings
Refresh Integration
Frequently Asked Questions


Setup Procedure

1. Account Integration Settings

Preliminary Check

On the Microsoft 365 (Office 365) side, regarding the federation status of Azure Active Directory (hereinafter AD),
please check the following:

  1. ○○.onmicrosoft.com and the primary domain cannot be federated (integrated).
    Please confirm that the domain you want to integrate is not the primary domain.
  2. The domain to be federated (integrated) must not already be federated.
    Please confirm that the "Status" shows "Verified."

    01_1.png

Setup Method

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button for "Office 365 Integration."

    02.png
  2. Click "Set up Office 365." (You will be redirected to Microsoft 365 (Office 365).)

    03.png
  3. Log in to Microsoft 365 (Office 365) with an administrator account.
    Note: We recommend using an administrator account with a UPN that includes xxx.onmicrosoft.com for the 365 integration settings.
    04__1_.png
  4. Click "Accept" to grant TrustLogin access permission to Microsoft 365 (Office 365).

    05.png
  5. The account selection screen will appear again. Select the account you want to federate.

    04.png
  6. Check "Consent on behalf of your organization" and click Accept.

    06.png
  7. When the list of domain names registered in Microsoft 365 (Office 365) is displayed, setup is complete.

2. Adding Members

Preliminary Check

Note: Before integration, the TrustLogin member ID must match the Microsoft 365 (Office 365) username.

Integration Behavior List

Microsoft 365 (Office 365)
User
TrustLogin User Integration Behavior
Account already exists
aaa@example.com

Microsoft 365 (Office 365) user and username

match
aaa@example.com

Integration is completed, and the TrustLogin account information is synced to Microsoft 365 (Office 365).
aaa@example.com
Account already exists
aaa@example.com

Microsoft 365 (Office 365) user and username

do not match
aac@example.com

Because integration with Microsoft 365 (Office 365) does not occur, the Microsoft 365 (Office 365) user (aaa@example.com) remains as is, but is not managed by TrustLogin.

In addition, a new Microsoft 365 (Office 365) user is created using the TrustLogin username (aac@example.com).

Account does not exist

-

New account created

abc@example.com

Integration with Microsoft 365 (Office 365) occurs, and a new Microsoft 365 (Office 365) user (abc@example.com) is created.

If the domain names of Microsoft 365 (Office 365) and TrustLogin differ, the following behavior occurs.

Microsoft 365 (Office 365)
User
TrustLogin User Integration Behavior

Already in the "example.com" domain,

an account exists
aaa@example.com

The Microsoft 365 (Office 365) domain name and the domain name of the TrustLogin username do not match

aaa@forexample.com

Integration is completed, and the TrustLogin account information is synced to Microsoft 365 (Office 365).
aaa@example.com

Already in the "example.com" domain,

an account exists
aaa@example.com

The Microsoft 365 (Office 365) domain name and the domain name of the TrustLogin username do not match, and the part before the "@" also does not match
bbb@forexample.com

Because integration with Microsoft 365 (Office 365) does not occur, the Microsoft 365 (Office 365) user (aaa@example.com) remains as is, but is not managed by TrustLogin.

In addition, a new Microsoft 365 (Office 365) user is created using the TrustLogin username (bbb@example.com).

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button for "Office 365 Integration."

    01.png
  2. Members are assigned per "domain name" and "license."
    Note: The same member can be assigned to multiple domain names and multiple licenses. (Microsoft 365 (Office 365) licenses will be consumed accordingly.)
    Note: The Microsoft 365 (Office 365) user "user_name@o365-domain.com" is created from the user_name portion of the TrustLogin member name "user_name@tl-domain.com" combined with the assigned Microsoft 365 (Office 365) domain "o365-domain.com."

    Click the target domain name.

    office365-2.png
  3. A list of licenses associated with the target domain name will be displayed. Click the license you want to assign.

    office365-3.png
  4. Click "Add Member" displayed in the upper right. (You can also use "Add Group" to assign an entire group.)
    Note: When integrating users via a "Group," we have confirmed an issue where the Office 365 user cannot be deleted even if "Delete user in Office 365 after unlinking: ON" is set. If you are integrating via a group, please delete the user manually on the Office 365 side.



    office365-4.png

  5. Check the members you want to add, and click the "Register" button.

    03.png
  6. Confirm that the members have been added.

    04.png
  7. Microsoft 365 admin center will provision the member.

    For the member information sync field mapping table used when integrating TrustLogin with Microsoft 365 (Office 365), please see here.
    30.png


  8. Azure Active Directory portal will provision and sync the member.

    31.png


  9. Confirm that the "Office 365" app has been added to the "My Page" of the added member.

    Note: The Office 365 SAML app icon appears on the My Page of assigned users only when SAML integration is ON for the target domain name.

    12.png

  10. Clicking the app logs you in via SAML authentication.

    13.png

3. SAML Integration Settings

Important Notes

SAML integration settings are enabled on a per-domain basis.
Note: SAML authentication can be used with web browsers, desktop apps such as Outlook, and mobile apps.
Note: There have been reports of users integrated with Microsoft 365 (Office 365) being unable to log in to devices joined to Azure AD. Please note that we do not support using Microsoft 365 (Office 365) integrated users for Windows sign-in on devices joined to Azure AD.


Note: This can only be configured for domains other than the primary domain and onmicrosoft.com. For domain names where this cannot be configured, the "Edit" button and the "Enable automatic SSO (SAML) configuration" option will not be displayed, as shown in the image below.

office365-SAML2.png

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button for "Office 365 Integration."

    02.png
  2. Click the domain name for SAML integration.

    office365-2.png
  3. Click the "Edit" button.

    office365-SAML1.png
  4. Click the toggle next to "Enable automatic SSO (SAML) configuration" to turn it green ("ON"), and then click the "Save" button.

    When turning ON "Enable automatic SSO (SAML) configuration," you now need to select the "SSO source domain." This selects the domain that is the source of the SSO (SAML) configuration used by the target domain. If the target domain is a subdomain, specify the parent domain. If the target domain is itself the SSO source, the SSO target and source will be the same domain. By default, the same domain is specified for both the SSO target and source.
    Note: If a TrustLogin user is assigned to both a parent domain and a subdomain, SSO will only work for the domain that was assigned later.

    office365-SAML3.png
  5. An image will be displayed until the configuration is complete, so please wait a moment.

    office365-SAML4.png
  6. When the image display ends and the "Edit" button appears, SAML integration is complete.


    office365-SAML5.png

    Note: If you do not want the SAML app icon to appear on My Page, you can hide it by disabling the checkbox option below.

Refresh Integration

If a domain is added or removed on the Microsoft 365 (Office 365) side, you can refresh the integration to retrieve the latest domain information. This can also be used to refresh the integration when the token has expired.

  1. Click "Refresh Integration."
    koushin01.png
  2. Click "Yes" to grant consent as the Office 365 administrator.
    koushin02.png

  3. Perform the same steps as step 3 onward in the "Account Integration Settings" setup method.

Frequently Asked Questions

There is also a page that compiles frequently asked questions about Microsoft 365 (Office 365) integration. Please check it as needed.

Frequently Asked Questions and Answers about the Microsoft 365 (Office 365) Integration Feature