Bug 52413 - O365 setup: Instructions for Powershell setup outdated / Check SSO Setup functionality
Summary: O365 setup: Instructions for Powershell setup outdated / Check SSO Setup func...
Status: RESOLVED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Office 365
Version: UCS 5.0
Hardware: Other other
: P5 normal
Target Milestone: ---
Assignee: Iván.Delgado
QA Contact: Ole Schwiegert
URL: https://help.univention.com/t/problem...
Keywords:
Depends on:
Blocks:
 
Reported: 2020-11-22 21:10 CET by Erik Damrose
Modified: 2025-10-06 17:08 CEST (History)
7 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 6: Setup Problem: Issue for the setup process
Who will be affected by this bug?: 3: Will affect average number of installed domains
How will those affected feel about the bug?: 5: Blocking further progress on the daily work
User Pain: 0.514
Enterprise Customer affected?: Yes
School Customer affected?: Yes
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2025032421000042, 2025043021000136, 2025061221000069, 2025062321000173, 2025061221000069
Bug group (optional): Workaround is available
Customer ID:
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Erik Damrose univentionstaff 2020-11-22 21:10:34 CET
While working on a support ticket i tried to setup a new Windows VM to be able to use the powershell script offered by the wizard. The current description is outdated, so the SAML setup for the app cannot be completed easily.

I simultaneously tried to setup a VM with Win10 and Win7.

With Win10 and different Powershell Versions (i tried 6 and 7), i could not get the MSOnline module installed and be useable. The first report about this is quite old (Bug 48586), but we should recheck it, it should be able to setup the Connector using Win10. Disclaimer: I stopped my tests when i got the Win7 VM to work.

With Win7, the instructions are outdated, one needs at least to follow the instructions at [1] to install the MSOnline module.

Maybe we could setup a help article and link to it from the Wizard, instead of occasionally updating the App.

[1] 
https://dirteam.com/sander/2020/04/09/knowledgebase-you-receive-error-unable-to-download-when-you-try-to-install-the-azuread-or-msonline-powershell-module/
Comment 1 Erik Damrose univentionstaff 2021-09-09 12:49:04 CEST
We could also check if we can setup UCS as an external IdP in a different way. The Azure Portal currently has a section with a wizard to configure "External Identities" in the Azure Active Directory view.
Comment 2 Christina Scheinig univentionstaff 2025-04-30 13:06:50 CEST
The powershell script did not work in now two different customer environments.
I have to say, in my testenvironment it was still working, but for both customers, rewriting the script provided in the keycloak migration guide to use the new MG-Graph Modul worked and solved the keycloak connection.
Since we reached March, 30 2025 we should do something!

https://learn.microsoft.com/en-us/previous-versions/troubleshoot/microsoft-365/admin/connect-error-0x800488ee
Azure AD and MSOnline PowerShell modules are deprecated as of March 30, 2024. To learn more, read the deprecation update. After this date, support for these modules are limited to migration assistance to Microsoft Graph PowerShell SDK and security fixes. The deprecated modules will continue to function through March, 30 2025.

We recommend migrating to Microsoft Graph PowerShell to interact with Microsoft Entra ID (formerly Azure AD). For common migration questions, refer to the Migration FAQ. Note: Versions 1.0.x of MSOnline may experience disruption after June 30, 2024.

--------------------------------------------------------
Possible error message are:
"You do not have permissions to call this cmdlet".

OR
Set-MsolDomainAuthentication : Unable to complete this action. Try again later.
In Zeile:1 Zeichen:103
+ ... on Managed; Set-MsolDomainAuthentication -DomainName mein-verifizierter-dom-name.de - ...
+                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : OperationStopped: (:) [Set-MsolDomainAuthentication], MicrosoftOnlineException
    + FullyQualifiedErrorId : Microsoft.Online.Administration.Automation.InternalServiceException,Microsoft.Online.Adm
   inistration.Automation.SetDomainAuthentication
Comment 5 Christina Scheinig univentionstaff 2025-06-24 15:45:37 CEST
In addition this 
https://help.univention.com/t/howto-re-initialize-o365-after-certificate-change/14366
is also not working anymore, which is important, if the certificate is renewed.
Comment 6 Julia Bremer univentionstaff 2025-07-09 16:16:46 CEST
Currently the setup of the 365 connector does not work anymore.
While there is a workaround, this is a very bad first impression.

Additionally, this blocks migration to Keycloak for customers who want to upgrade to 5.2.
There will be a lot of customers trying to do that, since the summer vacation is now starting.

I increase the number of affected customers.
Comment 8 Mirac Erdemiroglu univentionstaff 2025-08-06 18:08:46 CEST
This works on 2 customer environments to solve the issue.
https://help.univention.com/t/how-to-setup-and-migrate-office-365-integration-with-keycloak/24414