Summary: This article contains step-by-step instructions on how to configure Cayosoft Administrator when Modern Authentication is enabled for various cloud services, or Azure AD Security Defaults setting is enabled for Azure AD.
Applies to: Cayosoft Administrator 7.1.0 or later
In January 2020 Microsoft has announced the availability of Security Defaults for Azure AD tenants. When enabled, this setting enforces multi-factor authentication (MFA) for all administrative roles members, including sign-in attempts from scripts and applications running on schedule or by non-interactive services like Cayosoft Administrator. In addition to MFA enforcement, Security Defaults disables legacy authentication for connections to cloud services.
Starting with version 7.1.0, Cayosoft Administrator supports Office 365 tenants with Security Defaults turned on, but additional configuration steps are required for Cayosoft Administrator to work correctly in such an environment. If you encounter this error in administrator Console: Office 365 connection failed. Immediate action required: navigate to Microsoft Office 365 settings and run the Check settings command. CayoAdmin Service could not connect to one of the managed platforms:
To fix this error perform the steps described in the Configuration section.
- Check that Office 365 connection account is enrolled to MFA:
- Sign-in to Office.com and set up 2-step verification for Office 365 connection account that is specified in Cayosoft Administrator Console in Microsoft Office 365 extension.
- In Cayosoft Administrator Console navigate to Home > Configuration > Connected Systems Extensions > Microsoft Office 365
- Click ... button next to Office 365 credentials
- On Specify Credentials window click Validate:
- Cayosoft Administrator checks if MFA prevents using Microsoft Office 365 connection account for non-interactive PowerShell command execution, and reports the issue. Click Next to exclude connection account from MFA enforcement.
- When prompted, sign in with a user that is a member of the Global Admins role in your Office 365 tenant.
- If Office 365 connection account is successfully excluded from MFA, you will get this message:
- Click Close
- Click OK on Specify Credentials window
- If Conditional Access Policies (CAP) are applied to Office 365 connection account, such an account can not be configured automatically. You should exclude Office 365 connection account from conditional access policies manually. See details in this KB: https://cayosoft.zendesk.com/hc/en-us/articles/360040551331
Connect to SharePoint Online when Modern Authentication is enabled
Due to current limitations in the Microsoft SharePoint module, when Modern Authentication for SharePoint is enabled, connecting to SharePoint Online service requires adding a registry subkey on the client computer to avoid connection issues. This key forces Modern Authentication when connecting to SharePoint Online. For details please see this article: Troubleshooting connection to SharePoint Online – Cayosoft Help Center.