You enabled Azure AD Seamless Single Sign-On with Password Hash Synchronization. Users signed in to domain-joined Windows 10 devices get SSO in Microsoft Edge, but Google Chrome and Mozilla Firefox still prompt for credentials. You need to minimize prompts in Chrome and Firefox for on-premises users. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure Chrome and Firefox policies to allow Integrated Windows Authentication for https://login.microsoftonline.com and https://autologon.microsoftazuread-sso.com..
Why this is the answer
The correct solution is to configure Chrome and Firefox policies to allow Integrated Windows Authentication (IWA) for the specified Azure AD URLs. Seamless SSO relies on Kerberos for domain-joined devices. While Edge automatically supports IWA, Chrome and Firefox require explicit configuration to trust the Azure AD URLs for Kerberos authentication. This allows them to pass the user's Kerberos ticket to Azure AD, enabling SSO. Converting to federated authentication with AD FS is unnecessary and more complex, as Seamless SSO already provides a good solution. Manually creating the AZUREADSSOACC account is part of the Seamless SSO setup but doesn't address browser-specific behavior. Enabling Pass-through Authentication instead of Password Hash Synchronization wouldn't resolve the browser compatibility issue, as both rely on similar Kerberos mechanisms for Seamless SSO. Adding URLs to Trusted Sites helps with Internet Explorer/Edge but not Chrome or Firefox.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed