Configuring Kerberos Single Sign-On (iOS)

Before you begin

You must have Manage Profile permissions. See General Permissions.

About this task

Kerberos SSO enables administrators to configure centralized authentication across multiple applications on iOS devices. Once a user logs in to one app, the credentials are reused across other authorized apps without additional sign-ins. This improves user experience while maintaining enterprise security.

Procedure

  1. Create or edit a Reactive iOS/ Shared iPad User profile. See Creating a Profile and Editing a Profile.
  2. From the Security & Restrictions configurations list, add the Kerberos SSO configuration.
    Selecting the Kerberos SSO profile configuration in a Reactive iOS profile.
  3. Enter the required Kerberos authentication details:
    • Account Name: Enter the SSO account name.
    • Principal Name: Enter the unique Kerberos Principal name.
    • Realm: Enter the associated Kerberos realm.
    • Renewal Certificate (iOS 8+): Select a Renewal Certificate from available PKI, SCEP, or grouped certificate lists (if applicable).
      Note: This option is disabled if you do not include certificates or templates.
    The Kerberos SSO iOS configuration window.
    Tip: You can specify the Kerberos Principal Name using macros such as:
    • Active Directory User Principal Name used during enrollment
    • Enrolled User Domain
    • Enrolled User Username
    • Enrolled User email
  4. Select (Add) to specify target applications that will use Kerberos SSO.

    Alternatively, enter a URL prefix in the format http://www.example.com.

  5. Save the configuration and assign the profile to your target devices. See Assigning a Profile.

Results

You have successfully configured Kerberos SSO for your iOS devices. The profile is now available in the Profiles view.