Pass User Principal Name (UPN) From Smart Card Login To Office 365 For Activation?


we have bit of unusual scenario here we're trying resolve.  use smart card login our primary method authenticate our active directory environment.   x.509 smart card certificates mapped altsecurityidentities attribute on ad user accounts , upn mapping disabled via usesubjectaltname=0 value in registry.

the issue encountering related our office 365 cloud email , productivity solution.  when log workstation using smart card, office 365 applications (word, excel, outlook, etc) prompt users enter email address activate product instead of activating automatically.  if log workstation using username/password instead of smart card, autoactivation works fine.  not want users prompted activate , according microsoft documentation

if environment configured synchronize office 365 , network user accounts, user won’t see prompts. office 365 proplus should automatically able necessary information user’s account in office 365.

our environment configured office 365 using adfs , autoactivation works fine long user logs workstation username/password.  difference can see between smart card login vs username/password login running whoami /upn command line returns samaccountname in smart card scenario whereas same command returns upn in username/password scenario.  we're assuming our problem upn not being returned , therefore cannot passed through adfs/o365 perform license activation in smart card scenario. our understanding o365 accept upn (o365 account format) activation.

there way in can ensure upn being sent adfs/o365 users signed on domain machine using smart card?



Windows Server  >  Security



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...