Genesys Cloud - Main

 View Only

Discussion Thread View
  • 1.  Genesys Cloud desktop app Micorosft Entra IDP sign in browser

    Posted 30 days ago
    Edited by Carter Wilson 30 days ago

    Hello, when signing in to the Genesys Cloud desktop app and choosing an IDP such as Microsoft Entra, the app appears to launch some built in version of a Chromium browser to start the sign in process. However, for Microsoft SSO to work in Chromium browsers other than Edge, an extension called Microsoft Single Sign On is required.

    Without this extension, users are required to complete a full sign in rather than be able to automatically authenticate with their computer account. Additionally, some Conditional Access options such as requiring an Entra Registered device or MDM Compliant Device is unable to be used without that extension, or the Edge browser.

    Is there some way that the app can be configured to simply use your default browser to complete sign in, or is it possible to force install an extension on whatever kind of Chromium it is using?


    #SystemAdministration

    ------------------------------
    Carter Wilson
    ------------------------------



  • 2.  RE: Genesys Cloud desktop app Micorosft Entra IDP sign in browser

    Posted 29 days ago

    Hello Carter,

    I'm not aware of any such limitation like that with SSO. It should use your current browser.

    Does the same happen if you try to access Genesys from a web browser? You may want to take a look at this Resource Center article to make sure things are configured properly.



    ------------------------------
    Jason Kleitz
    Online Community Manager/Moderator
    ------------------------------



  • 3.  RE: Genesys Cloud desktop app Micorosft Entra IDP sign in browser

    Posted 29 days ago

    Hi Jason,


    Thanks for the reply. When I login via a web browser, everything works as expected. But when using the Genesys Cloud App, there is some browser built inside the app that is displaying the login page:


    and if our conditional access policies require something like an entra registered device, domain joined device, etc... I get this error message asking me to install the extension:


    I can exclude our entra Genesys SSO from Conditional Access policies that require this, but that is not ideal as I would like to lock down login to managed and compliant devices only.


    ------------------------------
    Carter Wilson
    ------------------------------



  • 4.  RE: Genesys Cloud desktop app Micorosft Entra IDP sign in browser
    Best Answer

    Posted 29 days ago

    I see in the documentation you provided:

    • The Genesys Cloud desktop app does not support the installation of browser extensions. If you have configured an Azure Conditional Access policy that requires a browser extension, you will need to use a Genesys Cloud supported browser that has the Microsoft Entra ID extension installed. Single sign-on will not work using the desktop app in this configuration.

    It sounds like this is not going to be possible. I guess we will have to consider this security limitation and if we want to allow use of the desktop app.



    ------------------------------
    Carter Wilson
    ------------------------------



  • 5.  RE: Genesys Cloud desktop app Micorosft Entra IDP sign in browser

    Posted 26 days ago

    Carter,

    To what's worth, using the Desktop App has been (sometimes) problematic when Windows updates take/took place, somehow breaking the link and denying the user to reach the Login page.  Upon using the org bookmarked Login URL, everything worked fine.

    Have you experienced that? 



    ------------------------------
    Oswaldo Ganoza
    Sr. Enterprise Solutions Consultant
    ------------------------------



  • 6.  RE: Genesys Cloud desktop app Micorosft Entra IDP sign in browser

    Posted 26 days ago

    Hi Jason, 

    Having been exploring what Carter brought up in this post, i ran into the following step:

    https://help.mypurecloud.com/articles/add-microsoft-adfs-single-sign-provider/

    Add a Relying Party Trust

    1. Go to Administrative Tools > AD FS. -> Is this within GC ADMIN or AD FS Admin?
    2. In the console tree, go to AD FS > Trust Relationships > Relying Party Trusts.
    3. To open the wizard, click Add Relying Party Trust.
    4. On the Select Data Source page, click Enter data about the replying party manually.
    5. On the Specify Display Name page, enter a name for the replying party (that is Genesys Cloud).

    Thanks,

    Ozzie.



    ------------------------------
    Oswaldo Ganoza
    Sr. Enterprise Solutions Consultant
    ------------------------------



Need Help finding something?

Check out the Genesys Knowledge Network - your all-in-one access point for Genesys resources