Integrate Microsoft Office 365 with Identity as a Service

You must configure Microsoft Office 365 for Identity as a Service before configuring mobile Microsoft Office 365 applications for single sign-on.

Note: The user attributes received through Active Directory (AD) synchronization are retrieved as strings. If an attribute comes in as a byte array, it is base64 encoded before being used as part of the SAML response.

Note: When integrated with Identity as a Service, Microsoft Office 365 accounts are configured for single logout (SLO). Logging out of Office 365 automatically logs the user out of Identity as a Service. The user is not logged out of other SAML application accounts by logging out of Microsoft Office 365 and logging out of an Identity as a Service account does not log the user out their Microsoft Office 365 account.

Note: This guide was tested using previous versions of Identity as a Service and Microsoft Office 365. Other versions of Microsoft Office 365 may require integration and configuration steps that differ from those documented in this procedure. For newer versions of Microsoft Office 365, this integration guide may be used as an initial approach for integrating Microsoft Office 365. In the event of other issues, contact support@entrust.com for assistance.

To integrate Microsoft Office 365 with Identity as a Service, you must do the following:

Step 1: Complete the following prerequisites

       Create an ImmutableID (for example, O365 ImmutableID) custom user attribute for your users

       Optional: Map the Immutable ID attribute to the directory attribute

       Confirm that your Office 365 account supports single sign-on (SSO) and Federation by reviewing Microsoft's Plan Comparisons.

Step 2: Prepare Microsoft Office 365 for configuration

Step 3: Add Microsoft Office 365 to Identity as a Service

Step 4: Create a resource rule to protect access to Microsoft Office 365

Step 5: Download the Metadata file from Identity as a Service

Step 6: Prepare users for Microsoft Office 365 access

Step 7: Configure Microsoft Office for Identity as a Service using PowerShell