Set up NTLM-based single sign-on to transparently authenticate on-premises Active Directory users using their Windows logon credentials.
NTLM-based single sign-on applies only to user devices in an Active Directory domain. Therefore, make sure you have joined desired user devices to your on-premises Active Directory domains.
Consider the following limitations when planning NTLM-based single sign-on:
Internet Access cannot authenticate users who do not use the Secure Access Module and connect from outside corporate network locations identified by managed Internet Access Cloud Gateways.
If you use an Active Directory Global Catalog server, Internet Access rule mismatch might occur for users with the same user name in your organization.
Protocol |
Microsoft Active Directory |
Microsoft Active Directory Global Catalog |
---|---|---|
LDAP |
389 |
3268 |
LDAPS |
636 |
3269 |
All your on-premises Active Directory users are authenticated with the specified on-premises Active Directory server through this gateway.
The on-premises gateway uses listening port 8089 for the authentication.
By default, Internet Access uses the built-in CA certificate for HTTPS inspection to sign the server certificate for user authentication. To use a Custom certificate, upload your own certificate and private key, and provide the passphrase and confirm passphrase.
Make sure that the Common Name (CN) or Subject Alternative Name (SAN) of the certificate matches the hostname of the selected gateway.
It might take a few minutes for the configuration to take effect.
Setting up auth proxy: Internet Access is applying the NTLM-based single sign-on settings on the on-premises gateway.
Used as auth proxy: The on-premises gateway is successfully configured as the authentication proxy.
Auth proxy error: An error occurred when the on-premises gateway attempted to communicate with the Active Directory server or Trend Vision One, or when the Zero Trust Secure Access On-Premises Gateway service is disabled or uninstalled on the Service Gateway appliance or the appliance is disconnected.
Supported Browser |
Settings |
---|---|
Mozilla® Firefox® |
|
Google Chrome™ Microsoft Edge™ (Chromium-based) |
|