AAD Sign-Ins, but no Local AD sign-ins

Jinseng 41 Reputation points
2020-04-27T20:56:21.36+00:00

We are configured with Azure AD Sync and ADFS for authentication. When a user signs in, they're directed to ADFS for authentication, and then back to the O354/Azure application. This records a Sign-In in the Azure Sign-Ins log, and it updates the LastLogon or LastLogonTimestamp attribute in our local Active Directory. We have one user with many Office 365 Exchange Online logins in the Azure Sign-Ins log, but their Local active directory attribute is not updated. Any thoughts on how this is happening? All of their AAD Sign-Ins for the last 7 days are for Office 365 Exchange Online, so I'm wondering if they're using Outlook and it just keeps updating an authentication token with AAD so it rarely hits our local ADFS server. Does that sound reasonable?

Thanks for any thoughts you have.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,199 questions
0 comments No comments
{count} votes

Accepted answer
  1. Pierre Audonnet - MSFT 10,166 Reputation points Microsoft Employee
    2020-04-30T20:23:18.417+00:00

    The user goes to ADFS only if does not already have a valid token for Azure AD.

    If the user is connected on an Hybrid Azure AD joined device for example, the user will have a PRT and the chance to go back to ADFS are really low.


0 additional answers

Sort by: Most helpful