Single Sign On

Single Sign On (SSO) allows user credentials to be used across apps. To view, edit, or delete SSO policies:

Note:

SSO policies are only supported on iOS 7+ devices.

  • 1. To view, edit, or delete SSO policies for the entire organization, navigate to the dashboard home page. To view, edit, or delete SSO policies for a group or sub group, navigate to that group or sub group.
  • 2. Click Policies.
  • 3. Click Single Sign On. The following will be displayed:

Single Sign On

Configurable SSO settings:

Field Description OS Supported
Name Enter a display name for the SSO account iOS7+
Principal Name Enter the Kerberos principal name, which will be in all apps supporting SSO iOS7+
Identity certificate From the dropdown list select the SCEP policy.
Note: Before you can use this feature you must first configure a SCEP policy
iOS 7+
Realm Enter the Kerberos realm name, which will be in all apps supporting SSO iOS7+
URL Patterns Click the plus sign (+) and enter a URL prefix that must be matched to use this SSO account for Kerberos authentication over HTTP. Use the minus sign () to delete a URL prefix iOS7+
App Identifiers Click the plus sign (+) and enter an app identifier (for example, com.apple.mobilesafari) or select an installed app from the dropdown list for an app that will be allowed to use SSO. Use the minus sign () to delete an app identifier.
Note: If this field is blank then all apps that can use SSO will be allowed to use it.
iOS7+