You can set up Office 365 MFA from either your own PC or from the computer where your DualShield MFA server is running.
| Table of Contents |
|---|
Download PS Script
Download this PowerShell script: setup-o365-sso-v2.ps1, and save it to a local folder.
Download IdP Metadata from DualShield
If you are operating from your own PC, then first check whether or not you have access to your DualShield SSO service.
...
| Expand |
|---|
In your DualShield admin console, select "SSO | SSO Servers". Click the context menu of the SSO server, then select "Download IdP Metadata" Save the IdP Metadata to a file, eg. "dualshield-idp-metadata.xml", in the same folder where the PowerShell script "setup-o365-sso.ps1" is saved. |
Connect to Office 365 Powershell
Connect to Office 365 Powershell as shown below:
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|
Check Current Federation Settings
First, check the current settings by run ning the following command:
| Code Block | ||
|---|---|---|
| ||
get-MsolDomainFederationSettings -domain 'domain name' |
in which 'domain name' is the domain name of your Office 365.
Enable SSO Federation in Office 365
Run Windows PowerShell as administrator
When you are ready to enable DualShield MFA on your Office 365 domain, take one of the steps below.
a) If you had to download the metadata file, then execute the following command in PowerShell
| Code Block | ||
|---|---|---|
| ||
.\setup-o365-sso.ps1 -protocol WSFED -domain 'o365 domain name' -appname 'application name' -spname 'service provider name' -metadatametafile '.\sso metadata file' |
b) Otherwise, execute the following command in PowerShell
...
| Parameter | Remarks |
|---|---|
| -protocol | WSFED |
| -domain | the domain name of your Office 365 |
| -appname | the application name in DualShield for Office 365 |
| -spname | the service provider name in DualShield for Office 365 |
| -metadatametafile | the metadata file name of your DualShield SSO |
| -fqdn | the FQDN of your DualShield SSO service |
| -port | the port number of your DualShield SSO service |
Example 1: Using FQDN
.\setup-o365-sso.ps1 -protocol WSFED -domain 'opensid.net' -appname 'Office365' -spname 'Office365WSFED' -fqdn 'dualshield.opensid.net' -port '8074'
| Expand |
|---|
Example 2: Using Metadata File
.\setup-o365-sso.ps1 -protocol WSFED -domain 'opensid.net' -appname 'Office365' -spname 'Office365WSFED' -metafile '.\idp.dualshield.opensid.net.xml'
| Expand |
|---|
Notes:
To verify that the change was successful, run the following command:
...





