Office 365 SSO with different internal and external domain names


I'm trying to get SSO to work with Office 365 and Sharepoint online and I'm getting really confused. My internal domain is "" and my external name is "". is added as a domain in O365, but is not. Should I put on a external DNS server and add it as a domain in O365? Would that make it so my internal users wouldn't have to sign into

Best Answer

When you sync with Office 365 your internal domain must be a routable address and this should be assigned to users UPN suffix. When you sync users you will then use the same logon as you would internally ( to login to Office 365.

it's fine to have your Federated endpoint accessible from (i.e., as the server will be configured to talk to the internal systems. This won't change the name users will use to login.