ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Microsoft Outage affected Federated Domains

    Scheduled Pinned Locked Moved IT Discussion
    26 Posts 5 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403
      last edited by

      And no one in the ADFS team (including managers) is answering calls...

      Did something happen where this team is located?

      scottalanmillerS coliverC 2 Replies Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @DustinB3403
        last edited by

        @DustinB3403 said in Microsoft Outage affected Federated Domains:

        And no one in the ADFS team (including managers) is answering calls...

        Did something happen where this team is located?

        You sure that they have a team?

        1 Reply Last reply Reply Quote 0
        • coliverC
          coliver @DustinB3403
          last edited by

          @DustinB3403 said in Microsoft Outage affected Federated Domains:

          And no one in the ADFS team (including managers) is answering calls...

          Did something happen where this team is located?

          I'm not convinced they have a team.

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @coliver
            last edited by

            @coliver said in Microsoft Outage affected Federated Domains:

            @DustinB3403 said in Microsoft Outage affected Federated Domains:

            And no one in the ADFS team (including managers) is answering calls...

            Did something happen where this team is located?

            I'm not convinced they have a team.

            I've seen no evidence of one.

            1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender @scottalanmiller
              last edited by

              @scottalanmiller said in Microsoft Outage affected Federated Domains:

              @coliver said in Microsoft Outage affected Federated Domains:

              @DustinB3403 said in Microsoft Outage affected Federated Domains:

              @coliver Do you have a hybrid domain?

              Nope, but we do use ADFS for authentication.

              Not a good idea. 😉 That's why we warn people about that. It's not very useful but carries a lot of risk.

              Not very useful? A single username/password for O365 and your local domain isn't useful?

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @Dashrender
                last edited by

                @Dashrender said in Microsoft Outage affected Federated Domains:

                @scottalanmiller said in Microsoft Outage affected Federated Domains:

                @coliver said in Microsoft Outage affected Federated Domains:

                @DustinB3403 said in Microsoft Outage affected Federated Domains:

                @coliver Do you have a hybrid domain?

                Nope, but we do use ADFS for authentication.

                Not a good idea. 😉 That's why we warn people about that. It's not very useful but carries a lot of risk.

                Not very useful? A single username/password for O365 and your local domain isn't useful?

                ADFS is not what provides that. ADFS is what creates the co-dependency where if either side fails, everything fails. You are leaping to conclusions that ADFS = single sign on. Since you have that feature without ADFS you can't make such an assumption.

                DashrenderD 1 Reply Last reply Reply Quote 0
                • DashrenderD
                  Dashrender @scottalanmiller
                  last edited by

                  @scottalanmiller said in Microsoft Outage affected Federated Domains:

                  @Dashrender said in Microsoft Outage affected Federated Domains:

                  @scottalanmiller said in Microsoft Outage affected Federated Domains:

                  @coliver said in Microsoft Outage affected Federated Domains:

                  @DustinB3403 said in Microsoft Outage affected Federated Domains:

                  @coliver Do you have a hybrid domain?

                  Nope, but we do use ADFS for authentication.

                  Not a good idea. 😉 That's why we warn people about that. It's not very useful but carries a lot of risk.

                  Not very useful? A single username/password for O365 and your local domain isn't useful?

                  ADFS is not what provides that. ADFS is what creates the co-dependency where if either side fails, everything fails. You are leaping to conclusions that ADFS = single sign on. Since you have that feature without ADFS you can't make such an assumption.

                  oh - didn't know that, how does do you get single sign on then?

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @Dashrender
                    last edited by

                    @Dashrender said in Microsoft Outage affected Federated Domains:

                    @scottalanmiller said in Microsoft Outage affected Federated Domains:

                    @Dashrender said in Microsoft Outage affected Federated Domains:

                    @scottalanmiller said in Microsoft Outage affected Federated Domains:

                    @coliver said in Microsoft Outage affected Federated Domains:

                    @DustinB3403 said in Microsoft Outage affected Federated Domains:

                    @coliver Do you have a hybrid domain?

                    Nope, but we do use ADFS for authentication.

                    Not a good idea. 😉 That's why we warn people about that. It's not very useful but carries a lot of risk.

                    Not very useful? A single username/password for O365 and your local domain isn't useful?

                    ADFS is not what provides that. ADFS is what creates the co-dependency where if either side fails, everything fails. You are leaping to conclusions that ADFS = single sign on. Since you have that feature without ADFS you can't make such an assumption.

                    oh - didn't know that, how does do you get single sign on then?

                    AD Sync. That's the recommended method. You only use ADFS if you "have to" for certain advanced features. The Sync method is asynchronous and just keeps the two up to date with each other. If either goes down the other doesn't notice.

                    coliverC 1 Reply Last reply Reply Quote 0
                    • coliverC
                      coliver @scottalanmiller
                      last edited by coliver

                      @scottalanmiller said in Microsoft Outage affected Federated Domains:

                      @Dashrender said in Microsoft Outage affected Federated Domains:

                      @scottalanmiller said in Microsoft Outage affected Federated Domains:

                      @Dashrender said in Microsoft Outage affected Federated Domains:

                      @scottalanmiller said in Microsoft Outage affected Federated Domains:

                      @coliver said in Microsoft Outage affected Federated Domains:

                      @DustinB3403 said in Microsoft Outage affected Federated Domains:

                      @coliver Do you have a hybrid domain?

                      Nope, but we do use ADFS for authentication.

                      Not a good idea. 😉 That's why we warn people about that. It's not very useful but carries a lot of risk.

                      Not very useful? A single username/password for O365 and your local domain isn't useful?

                      ADFS is not what provides that. ADFS is what creates the co-dependency where if either side fails, everything fails. You are leaping to conclusions that ADFS = single sign on. Since you have that feature without ADFS you can't make such an assumption.

                      oh - didn't know that, how does do you get single sign on then?

                      AD Sync. That's the recommended method. You only use ADFS if you "have to" for certain advanced features. The Sync method is asynchronous and just keeps the two up to date with each other. If either goes down the other doesn't notice.

                      We're using it for SSO and some of the advanced features that you mentioned. As well as 20 or so other apps that integrate with it for SSO.

                      1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender
                        last edited by

                        the idea of ADFS definitely sounds cool - it would be awesome to not have to call the hospital when we hire a new employee, through ADFS our new employee just works, but the problems like Dustin had really kinda of make it untenable if they are common place.

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @Dashrender
                          last edited by

                          @Dashrender said in Microsoft Outage affected Federated Domains:

                          the idea of ADFS definitely sounds cool - it would be awesome to not have to call the hospital when we hire a new employee, through ADFS our new employee just works

                          But you get that without ADFS as well.

                          1 Reply Last reply Reply Quote 0
                          • DustinB3403D
                            DustinB3403
                            last edited by

                            So the way ADFS works (here) is that when a client attempts to access say, email, they hit microsoft, which forwards the request to our exchange server to confirm the user details, and then our server redirects the request back to microsoft to access email.

                            This is a long handshake. Just have autodiscover setup and configured that Microsoft is syncing our details from exchange, and allowing people to authenticate against what microsoft has for email is way "cleaner".

                            And way less of a headache (like the past 4 days)

                            DashrenderD 2 Replies Last reply Reply Quote 1
                            • DashrenderD
                              Dashrender @DustinB3403
                              last edited by

                              @DustinB3403 said in Microsoft Outage affected Federated Domains:

                              So the way ADFS works (here) is that when a client attempts to access say, email, they hit microsoft, which forwards the request to our exchange server to confirm the user details, and then our server redirects the request back to microsoft to access email.

                              This is a long handshake. Just have autodiscover setup and configured that Microsoft is syncing our details from exchange, and allowing people to authenticate against what microsoft has for email is way "cleaner".

                              And way less of a headache (like the past 4 days)

                              apparently that is what AD sync is for. why are you using ADFS and not AD sync?

                              DustinB3403D 1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @DustinB3403
                                last edited by

                                @DustinB3403 said in Microsoft Outage affected Federated Domains:

                                So the way ADFS works (here) is that when a client attempts to access say, email, they hit microsoft, which forwards the request to our exchange server to confirm the user details, and then our server redirects the request back to microsoft to access email.

                                This is a long handshake. Just have autodiscover setup and configured that Microsoft is syncing our details from exchange, and allowing people to authenticate against what microsoft has for email is way "cleaner".

                                And way less of a headache (like the past 4 days)

                                I suppose I see what you're saying AD sync can give you this. So what other features of ADFS is @coliver getting that AD sync doesn't provide?

                                DustinB3403D 1 Reply Last reply Reply Quote 0
                                • DustinB3403D
                                  DustinB3403 @Dashrender
                                  last edited by

                                  @Dashrender said in Microsoft Outage affected Federated Domains:

                                  @DustinB3403 said in Microsoft Outage affected Federated Domains:

                                  So the way ADFS works (here) is that when a client attempts to access say, email, they hit microsoft, which forwards the request to our exchange server to confirm the user details, and then our server redirects the request back to microsoft to access email.

                                  This is a long handshake. Just have autodiscover setup and configured that Microsoft is syncing our details from exchange, and allowing people to authenticate against what microsoft has for email is way "cleaner".

                                  And way less of a headache (like the past 4 days)

                                  apparently that is what AD sync is for. why are you using ADFS and not AD sync?

                                  I wasn't included in these conversations, I'm just the janitor looking to clean the mess.

                                  1 Reply Last reply Reply Quote 0
                                  • DustinB3403D
                                    DustinB3403 @Dashrender
                                    last edited by

                                    @Dashrender said in Microsoft Outage affected Federated Domains:

                                    @DustinB3403 said in Microsoft Outage affected Federated Domains:

                                    So the way ADFS works (here) is that when a client attempts to access say, email, they hit microsoft, which forwards the request to our exchange server to confirm the user details, and then our server redirects the request back to microsoft to access email.

                                    This is a long handshake. Just have autodiscover setup and configured that Microsoft is syncing our details from exchange, and allowing people to authenticate against what microsoft has for email is way "cleaner".

                                    And way less of a headache (like the past 4 days)

                                    I suppose I see what you're saying AD sync can give you this. So what other features of ADFS is @coliver getting that AD sync doesn't provide?

                                    I honestly have no clue what features are included. I haven't done anything (besides the work over these past 4 days) to try and find what was broke.

                                    I'm not an exchange guy.

                                    1 Reply Last reply Reply Quote 0
                                    • 1
                                    • 2
                                    • 1 / 2
                                    • First post
                                      Last post