Hello,
Testing on a Win10 1803 client, domain joined, Azure AD joined (hybrid), all output from the client appears to indicate everything working properly. However, when using Microsoft Edge to access Office 365, the browser prompts for a username and password.
Chrome appears to do the SSO correctly. We also have the seamless sign-on configuration enabled, but from what I read, Hybrid AD Join is supposed to take precedence and provide a SSO experience in MS Edge.
Thanks for your help!
+----------------------------------------------------------------------+
| Device State
|
+----------------------------------------------------------------------+
AzureAdJoined : YES
EnterpriseJoined : NO
DeviceId : <redacted>
Thumbprint :<redacted>
KeyContainerId :<redacted>
KeyProvider : Microsoft Platform Crypto Provider
TpmProtected : YES
KeySignTest: : MUST Run elevated to test.
Idp : login.windows.net
TenantId :<redacted>
TenantName :<redacted>
AuthCodeUrl : https://login.microsoftonline.com/<redacted>
AccessTokenUrl : https://login.microsoftonline.com/<redacted>
MdmUrl :
MdmTouUrl :
MdmComplianceUrl :
SettingsUrl :
JoinSrvVersion : 1.0
JoinSrvUrl : https://enterpriseregistration.windows.net/EnrollmentServer/device/
JoinSrvId : urn:ms-drs:enterpriseregistration.windows.net
KeySrvVersion : 1.0
KeySrvUrl : https://enterpriseregistration.windows.net/EnrollmentServer/key/
KeySrvId : urn:ms-drs:enterpriseregistration.windows.net
WebAuthNSrvVersion : 1.0
WebAuthNSrvUrl : https://enterpriseregistration.windows.net/webauthn/<redacted>/
WebAuthNSrvId : urn:ms-drs:enterpriseregistration.windows.net
DeviceManagementSrvVersion : 1.0
DeviceManagementSrvUrl : https://enterpriseregistration.windows.net/manage/<redacted>
DeviceManagementSrvId : urn:ms-drs:enterpriseregistration.windows.net
DomainJoined : YES
DomainName :<redacted>
+----------------------------------------------------------------------+
| User State
|
+----------------------------------------------------------------------+
NgcSet : NO
WorkplaceJoined : YES
WorkAccountCount : 1
WamDefaultSet : YES
WamDefaultAuthority : organizations
WamDefaultId : https://login.microsoft.com
WamDefaultGUID : {<redacted>} (AzureAd)
AzureAdPrt : YES
AzureAdPrtAuthority : https://login.microsoftonline.com/<redacted>
EnterprisePrt : NO
EnterprisePrtAuthority :
+----------------------------------------------------------------------+
| Ngc Prerequisite Check
|
+----------------------------------------------------------------------+
IsUserAzureAD : YES
PolicyEnabled : NO
PostLogonEnabled : YES
DeviceEligible : YES
SessionIsNotRemote : YES
CertEnrollment : none
AadRecoveryNeeded : NO
PreReqResult : WillNotProvision
+----------------------------------------------------------------------+
| Work Acount 1
+----------------------------------------------------------------------+
WorkplaceDeviceId : <redacted>
WorkplaceThumbprint : <redacted>
WorkplaceIdp : login.windows.net
WorkplaceTenantId : 809929af-2d25-45bf-9837-089eb9cfbd01
WorkplaceTenantName : <redacted>
WorkplaceMdmUrl :
WorkplaceSettingsUrl :
NgcSet : NO