Autodesk SSO - Successful Implementation with Issues on Device ID Recognition and Conditional Access

Autodesk SSO - Successful Implementation with Issues on Device ID Recognition and Conditional Access

jzarczynski
Advocate Advocate
2,130 Views
7 Replies
Message 1 of 8

Autodesk SSO - Successful Implementation with Issues on Device ID Recognition and Conditional Access

jzarczynski
Advocate
Advocate

Hi,

 

I've successfully implemented a Single Sign-On (SSO) mechanism in our organization and it functions as expected in its basic variant. Our company places great emphasis on data protection, thus we have limited our users to only use Microsoft accounts within the organization's devices. In our case for Windows devices, these are hybrid joined to Azure Active Directory (AAD). To achieve this, we've configured an appropriate Conditional Access policy.

 

However, during the login to Autodesk from within the application, the Device ID is not passed, which, I suspect, doesn't allow users to log into their Autodesk accounts, as the device type isn't detected during login. Log fragment from an unsuccessful Autodesk account login initiated from Inventor:

aad problem.png

 

1.The same problem also occurs in Chrome when logging into other applications, but installing a specific plugin resolves it:

 

chrome.PNG

The mentioned plugin: Windows Accounts Plugin for chrome 

2.Similarly, this issue is also seen in Firefox, but Mozilla has implemented a solution as well:

 

firefox.png


Mentioned solution: Enable SSO login from Firefox 

 

3.In Microsoft Edge, everything works natively without any issues.

 

The same problem occurs when logging in from Autodesk applications like Inventor or Vault. Do you plan to address this issue in the same manner as Google and Mozilla Foundation?

 

I hope I have appropriately explained the problem. If you have any questions or need more information, I'm happy to provide more details. As it stands now, due to the conditional access restrictions, we can only log in through browsers configured as above. 

Additionaly, please take a look at sign-in logs from sucessfull login from browser (with implemneted solution for Chrome and Edge):

sucess_chrome.pngsucess_edge.png

 

Looking forward to your insights and suggestions.

Best Regards,

Jaromir

0 Likes
2,131 Views
7 Replies
Replies (7)
Message 2 of 8

TravisNave
Mentor
Mentor

Are your failures due to it being on a retired Windows 8 system?!?  

 



Travis Nave Send TravisNave a Private Message                                             Need help in your post? Mention me with @TravisNave



My Expert Contributions to the
Autodesk Forums:
FLEXnet License Admin | MSI Cleanup Utility | .NET Framework Cleanup Tool | IPv6 NLM Fix | adskflex.opt Options File | Combine .LIC Files
0 Likes
Message 3 of 8

jzarczynski
Advocate
Advocate

Hi @TravisNave.,

 

Thank you for providing an answer !

 

No,

The screen you're referring to is from the Microsoft Azure Active Directory Admin Center (AADAC), specifically from the device information section in the sign-in log.

 

It's related to logins initiated from Inventor, Autodesk Vault, or any other Autodesk app. In AADAC, these types of logins are visible as being done in Chrome 80 and on Windows 8.

That's obviously not true. In reality, all logins (from browsers and Inventor/Vault) were done from a Windows 10 computer.

 

I think you should modify the Autodesk Account login mechanism embedded in your application to allow passing device information, just like Mozilla/Google did.

All is described in article in 'Client Apps' section.

https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-acce... 

 

The conditional access I'm struggling with is a great way to provide more safety in Company by eliminating the risk of data leakage outside the organization (specifically by preventing logons from non-company devices).

 

Kind Regards,

Jaromir

0 Likes
Message 4 of 8

Kryst1an
Explorer
Explorer

Hi,

We are currently experiencing the same problem. Have you perhaps found a solution other than disabling the CA policy or upgrading the programs to version 2024?

From what I have been able to find the desktop app like AutoCAD 2023 or Revit 2023 for authentication use:
User agent: Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/5.15.10 Chrome/94.0.4606.126 Safari/537.36
which does not provide enough information like Device ID or Join Type to pass CA policy for domain joined devices.

Does Autodesk plan to find a solution or is the only solution as I mentioned to disable the CA policy or update the programs to version 2024?

Best regards,
Krystian

0 Likes
Message 5 of 8

Kryst1an
Explorer
Explorer

-

0 Likes
Message 6 of 8

Kryst1an
Explorer
Explorer

-

0 Likes
Message 7 of 8

jzarczynski
Advocate
Advocate

Hi,

I have successfully reached out to the Autodesk representative in charge of Single Sign-On (SSO). The only solution they've suggested is to upgrade your products to the 2024 version. Starting from this version, the login screen will utilize the default web browser instead of the embedded one.

 

Regards, 
Jaromir

0 Likes
Message 8 of 8

ralphsanchezATX
Advocate
Advocate

My users are currently on a mix of 2023 and 2025. I believe I was able to work around this by adding the Autodesk SSO app to the Exclude list in Target Resources for the conditional access policy.

I don't mind if folks sign into Autodesk apps or sites from non-Hybrid joined devices. We don't use any of Autodesk's cloud storage, so it shouldn't be a big deal.

0 Likes