Now in order to authenticate the client reaches out to and requests a Token, The intention here is to Get a Token from įrom this point onwards we will see that will redirect the client to Webticket Service Redirects the Client to Modern Auth Provider () Since the SFB user is homed Online, In Response Autodiscover will provide the Online Autodiscover webservices URL's names ( The client then submits this webticket to Autodiscover
#Skype online sign in password#
Once the password is provided, Webticket service will issue a Webticket to the client. The Client may receive a Password prompt (or previously saved password from credential manager is passed)
Here the Client has to Authenticate (NTLM). The Client then sends a POST request to Webticket Service The Client is then challenged and is provided the URL for Webticket service where it can request a Webticket SFB Client then sends a Request to Autodiscover to discover its pool for sign in. The Client is then redirected to Autodiscover SFB Client then sends a unauthenticated GET request to This should point to External web services URL (ON Premise Reverse Proxy) which in this case is SIP URI of the user - client Queries DNS for. My intention here is to explain what happens in the background when a SFB client signs in so that it helps engineers and customers troubleshooting issues related to Sign in and Authentication.ĭetailed Explanation of SFB online Client Sign in process with LOG Snippets: may not be standard terminology, I use them solely to make the understanding simpler.
Some of the terms I use to describe things like Modern Auth provider, O365 AD, Org ID etc. I have tried my best to ensure the information below is accurate. SFB Hybrid environment, SFB user is homed Online, ADFS is Configured, MA (Modern Auth) is Disabled ON premise but is Enabled in O365 First published on TECHNET on Apr 13, 2018