Windows Integrated Authentication (WIA) allows users to single sign-on to Deep Discovery Director (Consolidated Mode) using the domain credentials they used to sign on to an endpoint.
- Log on to a Windows Server installed with AD FS 4.0 or AD FS 5.0.
- Go to Start > All Programs > Administrative Tools to open the AD FS management console.
- Select AD FS > Service > Authentication Methods in the left navigation, and under the Actions area on the right, click Edit Primary Authentication Methods....
- On the Primary tab, under Intranet, ensure that Windows Authentication is enabled.
- Click OK.
- Log on to your Domain Controller.
- Go to Start > All Programs > Administration Tools > Group Policy Management.
- Select User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page.
- Double-click Site to Zone Assignment List to configure the settings.
- Select Enabled.
- Under Options, click Show.
- Add the Deep Discovery Director (Consolidated Mode) management console URL as Value name with a Value of 1.
- Click OK. The Deep Discovery Director (Consolidated Mode) management console URL is added to the Intranet zone.
- Select User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone.
- Double-click Logon options to configure the settings.
- Select Enabled.
- Under Options, click Automatic logon with current username and password.
- Click OK. This enables web browsers to automatically log on to the Deep Discovery Director (Consolidated Mode) management console with their current user name and password.
-
Deploy the updated group policy to your endpoints.
Note:Users who signed on to their endpoint using their domain credentials should now be able to single-sign on to Deep Discovery Director (Consolidated Mode).
If group policy deployment is blocked by the Windows Firewall, add an inbound rule to allow the deployment, and execute gpudate /force in an administrator command prompt on your endpoints to force endpoints to accept the new firewall policy.
Parent topic: Configuring Active Directory Federation Services