Step 1. Federate Office 365 to Workspace ONE
https://blog.simonelberts.nl/2022/01/federate-office-365-domain-to-third.html
Step 2. Certificate prompt
https://blog.simonelberts.nl/2022/06/certificate-prompt-certificate.html
Passwordless SSO with Workspace ONE Access and Certificate Authentication:
In this blog I will walk you through the configuration of enabling Certificate Authentication with Workspace ONE Access. This will provide a seamless Single Sign On experience without any user interaction needed to enter a username and/or password. Navigating to for example Office365 will be fully automated and no user interaction is required.
The experience is similar to that of the following video where you can see that the user doesn’t need to provide any input to authenticate on Office 365:
In a previous blog post i have described the steps to federate Office 365 to Workspace ONE Access which is a prerequisite for this configuration:
https://blog.simonelberts.nl/2022/01/federate-office-365-domain-to-third.html
(In this blog I will use the integrated AirWatch Certificate Authority but in production it is also possible to integrate with your own Certificate Authority link)
Prerequisites
Workspace ONE Access integrated with Active Directory
Workspace ONE UEM integrated with Active Directory
Integration enabled between UEM and Access
Federation of Office365 to Access (link)
KDC Certificate from AirWatch
SCEP profile for authentication
Configurations
Download the KDC certificate from Workspace ONE UEM console under Groups & Settings > All settings > System > Enterprise Integration > Workspace ONE Access > Configuration.
If it is not enabled, enable it and download the certificate.
NOTE: This certificate can only be generated at customer type OG
Go to Workspace ONE Access console
In the administration console Identity & Access Management tab, select Manage > Authentication Methods.
In the Authentication Methods section, click the Certificate (Cloud Deployment) icon.
Check the box for Enable Certificate Adapter
Configure the Certificate Service Auth Adapter page:
Upload the Root CA certificate that you obtained from the Workspace ONE UEM console.
Click Save.
You will see CN=<OGNAME>
Click Save.
Now got to UEM console go to Devices > Profiles & Resources > Profiles
Create a new Windows profile:
Select Windows Desktop
Select User Profile
Configure the General Page (create an assignment and fill in the name for the profile)
Configure SCEP Payload as follows:
Credential Source - AirWatch Certificate Authority
Certificate Authority - AirWatch Certificate Authority
Certificate Template - Certificate (Cloud Deployment)
Key Location - TPM If Present
Comments
Post a Comment