Migrating from AD FS to PTA for SSO to Office 365
This recipe shows how to change the sign-in method from federation with AD FS to PTA and Seamless SSO.
Getting ready
Ensure the organization has not implemented heavy customizations to the onload.js
page of the AD FS sign-in pages or relies on on-premises multi-factor authentication solutions.
To configure the sign-in method within Azure AD Connect, you'll need to sign in with an account that is a local administrator on the server dedicated to Azure AD Connect. As part of the following steps, you'll need to enter the credentials for these accounts:
- An account in Active Directory that is a member of the Enterprise Admins group
- An account in Azure AD that has the Global Administrator role or the Hybrid Identity Administrator role assigned
Ensure the Windows Server running Azure AD Connect can communicate with the internet without having to pass proxies and has IE ESC turned off.
If the organization...