MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.2k stars 21.36k forks source link

Why does this seem to work for some apps and not others? #55155

Closed accenture-eso closed 4 years ago

accenture-eso commented 4 years ago

My company is piloting this right now and has run into an issue where in some cases the device authentication flow gets invoked and in some cases it doesn't. The pattern looks like it might be related to the authentication protocol that the app uses with OIDC flows looking like they are supported and SAML and WS-Fed apps look like they are not. However, we aren't clear if we've diagnosed this correctly or not. Any comment either way? If this is the issue, will this be addressed at some point in the future? Let us know if we can supply more details.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

MarileeTurscak-MSFT commented 4 years ago

@accenture-eso thanks for this feedback. Can you provide any more details about the scenarios where it doesn't work? Without knowing more details about your setup I'm unsure what might be causing this.

I can get someone from the product team looped in or open a support case for you if needed.

accenture-eso commented 4 years ago

Yeah, I can definitely provide more details. I'd rather not share URLs or Fiddler traces here but I can definitely do that offline or through a different channel. My org has an Azure AD CXP person assigned, we have guest accounts in Microsoft's Teams environment and there is always email as well. We'd love to get some more feedback on this. We have an existing thread on this issue in our CXP collaboration teams site and our CXP person is trying to chase this down too but I figured it wouldn't hurt to post publicly here as well. Thanks!

MarileeTurscak-MSFT commented 4 years ago

Hi @accenture-eso ,

If you want to go over these traces, you can reach me at AzCommunity@microsoft.com. I'm also happy to open a support case for this if you would prefer.

Please provide for me: Subscription ID Any fiddler traces or screenshots The name of the CXP engineer working on your case

Closing this out but please feel free to reach out over email or on Microsoft Q&A.

accenture-eso commented 4 years ago

Did we get a response from the product team to go with this being closed?

Thanks!

Joe Kaplan Architecture and Strategy Lead – Technology Security Senior Manager Accenture CIO Identity and Access Management Organization

Mobile: (312) 953-9029 | E-mail: joseph.e.kaplan@accenture.commailto:joseph.e.kaplan@accenture.com

From: Marilee Turscak - MSFT notifications@github.com Sent: Thursday, June 11, 2020 11:13 AM To: MicrosoftDocs/azure-docs azure-docs@noreply.github.com Cc: Kaplan, Joseph E. joseph.e.kaplan@accenture.com; Mention mention@noreply.github.com Subject: [External] Re: [MicrosoftDocs/azure-docs] Why does this seem to work for some apps and not others? (#55155)

This message is from an EXTERNAL SENDER - be CAUTIOUS, particularly with links and attachments.


Closed #55155https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_MicrosoftDocs_azure-2Ddocs_issues_55155&d=DwMCaQ&c=eIGjsITfXP_y-DLLX0uEHXJvU8nOHrUK8IrwNKOtkVU&r=bMt_UnlytCDSQk0a4tILEzGjbczHChT6eBxxL_IAH8s&m=CDCHkevf-GgaUKFCbkJRHKTdP07w0nLdf9dXH1FNHe0&s=cTwKQdKGZMaSoY_MeIyzdhmx0AjWXyB5NODUJl00Nv8&e=.

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHubhttps://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_MicrosoftDocs_azure-2Ddocs_issues_55155-23event-2D3434910779&d=DwMCaQ&c=eIGjsITfXP_y-DLLX0uEHXJvU8nOHrUK8IrwNKOtkVU&r=bMt_UnlytCDSQk0a4tILEzGjbczHChT6eBxxL_IAH8s&m=CDCHkevf-GgaUKFCbkJRHKTdP07w0nLdf9dXH1FNHe0&s=uL43QIQM2IGVwTUYeaSQMacqn313s57xwhsRXuxsv0k&e=, or unsubscribehttps://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_notifications_unsubscribe-2Dauth_AA2QO54B5MR6A3RBXUIHTNDRWD7AJANCNFSM4NFAHOCQ&d=DwMCaQ&c=eIGjsITfXP_y-DLLX0uEHXJvU8nOHrUK8IrwNKOtkVU&r=bMt_UnlytCDSQk0a4tILEzGjbczHChT6eBxxL_IAH8s&m=CDCHkevf-GgaUKFCbkJRHKTdP07w0nLdf9dXH1FNHe0&s=lNXLSDXSJ4wO3OBl0GeOSbwoU1iQMeZrQVKqdStVHS8&e=.


This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security and assessment of internal compliance with Accenture policy. Your privacy is important to us. Accenture uses your personal data only in compliance with data protection laws. For further information on how Accenture processes your personal data, please see our privacy statement at https://www.accenture.com/us-en/privacy-policy.


www.accenture.com