Kerberos Single Sign-On (SSO) | iOS

About this task

Kerberos SSO enables device users to authenticate once instead of many times for different applications. Once authenticated to one app, the authentication credentials pass along to other apps. This configuration enables administrators to define single sign-on profiles and specify associated applications.

Procedure

  1. Create/ edit a Reactive iOS profile and add the Kerberos SSO configuration from the Security & Restrictions configurations list.
    Selecting the Kerberos SSO profile configuration in a Reactive iOS profile.
  2. Enter the required Kerberos authentication details:
    • Account Name: Enter the SSO account name.
    • Principal Name: Enter the unique Kerberos Principal name.
    • Realm: Enter the associated Kerberos realm.
    • Renewal Certificate (iOS 8+): Select a certificate from the available PKI, SCEP, or other grouped lists (if applicable).
      Note: Renewal Certificate option is disabled if you do not include certificates or templates in the profile.
    The Kerberos SSO iOS configuration window.
    Tip: You can specify the Kerberos Principal Name value using one of the available macros:
    • Active Directory User Principal Name used during enrollment
    • Enrolled User Domain
    • Enrolled User Username
    • Enrolled User email
  3. Select Add to specify target applications for SSO.

    Alternatively, specify a URL prefix in the format http://www.example.com.

  4. Save the configuration and assign the profile to your target devices.

Results

You have successfully configured a Kerberos SSO profile for iOS devices. The profile is now visible in the Profiles view.