Azure AD federation compatibility list

The following identity providers were tested for compatibility with Azure Active Directory by Microsoft, or by Oxford Computer Group on behalf of Microsoft, against a set of use cases common with Azure Active Directory. These tests were validated on or before April 2018.

Note: Microsoft tested only the federation functionality of these single sign-on scenarios. Microsoft did not perform any testing of the synchronization, two-factor authentication, etc. components of these single sign-on scenarios. Use of Sign-in by Alternate ID to UPN is also not tested in this program.

Important: Since these are third-party products, Microsoft does not provide support for the deployment, configuration, troubleshooting, best practices, etc. issues and questions regarding these identity providers. For support and questions regarding these identity providers, contact the supported third-parties directly. These third-party identity providers were tested for interoperability with Microsoft cloud services using WS-Federation and WS-Trust protocols only. Testing did not include using the SAML protocol.

Azure Active Directory

The following is the scenario support matrix for this sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

Modern Applications using ADAL such as Office 2016

Supported

None

For more information about using Azure Active Directory with AD FS see Active Directory Federation Services (ADFS).

For more information about using Azure Active Directory with Password sync see Azure AD Connect.

AuthAnvil Single Sign On 4.5

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

Integrated Windows Authentication is not supported

Rich client applications such as Lync, Office Subscription, CRM

Supported

Integrated Windows Authentication is not supported

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information, see AuthAnvil Single Sign On..

BIG-IP with Access Policy Manager BIG-IP ver. 11.3x – 11.6x

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Not Supported

Not Supported

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information about BIG-IP Access Policy Manager, see BIG-IP Access Policy Manager.

For the BIG-IP Access Policy Manager instructions on how to configure this STS to provide the single sign-on experience to your Active Directory Users, download the pdf BIG-IP.

CA SiteMinder 12.52 SP1 Cumulative Release 4

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information about CA SiteMinder, see CA SiteMinder Federation.

Dell One Identity Cloud Access Manager v7.1

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information about Dell One Identity Cloud Access Manager, see Dell One Identity Cloud Access Manager.

For the instructions on how to configure this STS to provide the single sign-on experience to your Office 365 Users, see Configure Office 365 Users.

DigitalPersona Composite Authentication

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

Integrated Windows Authentication is not supported

Rich client applications such as Lync, Office Subscription, CRM

Supported

Integrated Windows Authentication is not supported

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information see DigitalPersona Composite Authentication.

ForgeRock Identity Platform Access Management V5.x

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information see ForgeRock Identity Platform Access Management V5.x.

IBM Tivoli Federated Identity Manager 6.2.2

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information about IBM Tivoli Federated Identity Manager, see IBM Security Access Manager for Microsoft Applications.

IceWall Federation Version 3.0

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

Integrated Windows Authentication is not supported

Rich client applications such as Lync, Office Subscription, CRM

Supported

Integrated Windows Authentication is not supported

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information about IceWall Federation, see IceWall Federation Version 3.0 and IceWall Federation with Office 365.

MobileIron

Please note: certification expires 12 months from the validation date on 5/1/2019.

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

Integrated Windows Authentication is not supported

Rich client applications such as Lync, Office Subscription, CRM

Supported

Integrated Windows Authentication is not supported

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information about MobileIron see MobileIron or this password protected document.

NetIQ Access Manager 4.x

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information, see NetIQ Access Manager.

Optimal IDM Virtual Identity Server Federation Services

The following is the scenario support matrix this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

Integrated Windows Authentication

Email-rich clients such as Outlook and ActiveSync

Supported

 

For more information about client access polices see Limiting Access to Office 365 Services Based on the Location of the Client.

PingFederate 6.11, 7.2, 8.x

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

For the PingFederate instructions on how to configure this STS to provide the single sign-on experience to your Active Directory users, see one of the following:

RadiantOne CFS 3.0

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

Integrated Windows Authentication

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information about RadiantOne CFS, see RadiantOne CFS.

SecureAuth IdP 7.2.0

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

None

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

For more information about SecureAuth, see SecureAuth IdP.

Sign&go 5.3

The following is the scenario support matrix for this single sign-on experience:

Client

Support

Exceptions

Web-based clients such as Exchange Web Access and SharePoint Online

Supported

Kerberos Contracts supported

Rich client applications such as Lync, Office Subscription, CRM

Supported

None

Email-rich clients such as Outlook and ActiveSync

Supported

None

Sign&go 5.3 supports Kerberos authentication via configuration of a Kerberos Contract. For assistance with this configuration, please contact Ilex or view the setup guide Sign&go