Kerberos Single Sign-On (SSO) | iOS
About this task
Procedure
- Create/
edit a
Reactive iOS profile and add the Kerberos SSO
configuration from the Security & Restrictions
configurations list.
- Enter the required Kerberos authentication details:
- Account Name: Enter the SSO account name.
- Principal Name: Enter the unique Kerberos Principal name.
- Realm: Enter the associated Kerberos realm.
- Renewal Certificate (iOS 8+): Select a certificate from the available
PKI, SCEP, or other grouped lists (if applicable).Note: Renewal Certificate option is disabled if you do not include certificates or templates in the profile.
Tip: You can specify the Kerberos Principal Name value using one of the available macros:- Active Directory User Principal Name used during enrollment
- Enrolled User Domain
- Enrolled User Username
- Enrolled User email
- Select Add to specify target applications for
SSO.
Alternatively, specify a URL prefix in the format
http://www.example.com
. - Save the configuration and assign the profile to your target devices.