SSO O365 iOS/iPadOS Devices

L
lgn000
AZ Sint-Lucas Gent

Hi, 

Has anyone of you been able to successfully configure SSO for O365 apps in iPadOS devices? 

We made a Shared Device configuration in a parent group that relocates the device to the right child group at login in SOTI Mobicontrol Login app - this works. But we wanted to have the users also be logged in the O365 apps once they are in the right device group.

Anyone any experience with something similar? 

8 months ago
SOTI MobiControl
ANSWERS
RC
Raymond Chan Diamond Contributor
8 months ago

What are the version and build numbers of your MobiControl server?

What about those for your iPadOS devices?

What type of O365 licenses and AD/LDAP integration do you have on your system?

Could you please elaborate your problem and/or provide relevant screenshot(s)?

S
SSMOD@SOTI
8 months ago

Hello,

Yes, you can configure Office 365 (O365) apps in SOTI MobiControl (MC). This includes setting up app protection policies for Microsoft 365 apps on Android and iOS devices to ensure corporate data is secured within the apps.

To configure O365 apps, you generally need to ensure that certain prerequisites are met, such as having the necessary Azure AD licenses, integrating your Active Directory with Azure, and ensuring that the Microsoft Company Portal app is installed on the devices. You would also set up Conditional Access policies in Microsoft to control app access based on the compliance status of the managed devices.

For a detailed step-by-step guide on creating and managing these settings, you could refer to the specific sections of SOTI MobiControl documentation related to Microsoft 365 integration and app policies, such as Microsoft 365 Integration - App Protection Policy (v2024.1).

L
lgn000
8 months ago

Thanks both of you. I managed to configure SSO together with Shared Device. The issue is that when loging out of the SOTI Login app the user remains logged in in MS Authenticator. I reached out to SOTI support and the coming release should bring new things regarding integration of MS Authenticator so I guess I will just have to wait.