Table of Contents
Other Resources
Page History
...
You can configure realms to use Windows desktop SSO in any of the following ways:
Definition List | ||||
---|---|---|---|---|
|
Prerequisites
- SecureAuth IdP version 9.3
- SecureAuth IdP realm or integrated application with the following configured:
Microsoft Active Directory in use and integrated with SecureAuth IdP
UI Text Box size medium type info On the New Experience user interface in version 9.3, you can configure an Active Directory integration or SQL Server integration to be applied to applications made from App onboarding library templates. Configure the remaining components – for example, Workflow, Multi-Factor Methods, and Adaptive Authentication tabs – on the Classic Experience user interface.
- Set up custom identity SPN to leverage Integrated Windows Authentication (IWA)
Excerpt | ||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Enable universal Windows desktop SSO in the environmentThe most effective way to enable universal Windows desktop SSO is to push out a local intranet URL via Group Policy Object (GPO); however, end users can also configure their own devices and browsers to enable this feature. To enable Windows desktop SSO
|
...
- Go to the Workflow tab.
In the Workflow section, set the following:
Borderless_tables Default Workflow Set to Username only.
UI Text Box size medium type note To configure two-factor authentication (2FA), select Username | Second Factor.
Public/Private Mode Set to Public Mode Only. In the Custom Identity Consumer section, set the following:
Borderless_tables Receive Token Set to Token. Require Begin Site Set to True. Begin Site Use any of the following options:
- To include MFA and adaptive authentication in login workflow, set to Windows SSO. This method adds the Device Recognition layer, and is more secure.
- To skip the login workflow and go directly to the Post Authentication page, set to Windows SSO (skip workflow). This method does not include MFA, adaptive authentication, and increases performance.
Begin Site URL Depending on the Begin Site selection, this field is auto-populated with WindowsSSO.aspx or WindowsSSO2.aspx. User Impersonation Set to True. Windows Authentication Set to True. Use Kernel Mode To use custom Service Principal Names for Integrated Windows Authentication (Kerberos), set to True. AppPool Credentials To use custom Service Principal Names for Integrated Windows Authentication (Kerberos), set to True. - Click Save.