Desktop app
- In the navigation bar, click
.
- In the Users section, click User Authentication.
- On the User Authentication screen, in the Assign Authentication Methods to Applications section, select one of the following authentication methods for the desktop app from the Authentication Method list:
- LDAP Attribute: This option enables the desktop app to authenticate with an Active Directory attribute.
- Enter an Active Directory attribute in the Attribute field. The desktop app queries this attribute directly from the signed-in user's directory profile and sends it to the server. This option allows the desktop app to operate while sending less user information to the server. When this option is selected, the desktop app does not send Windows user names or domain names in sign on or check update query strings.
- Optionally, enter a valid LDAP URL in the Custom LDAP URL field. When a custom LDAP URL is specified, it overwrites the USERDOMAIN value from the local LDAP directory. Format the domain name using a regex to accept only URLs such as LDAP://<DOMAINNAME>.<TOP-LEVELDOMAIN>:<(Optional) PORT#>. Sample valid URLs:
- LDAP://DC=examplewebsite,DC=com
- LDAP://examplewebsite.com
- LDAP://DC=examplewebsite,DC=com,DC=org
- LDAP://examplewebsite.ca
- Optionally, select Fallback to Windows Authentication to configure the desktop app to authenticate with Windows Authentication if authentication with LDAP fails. This option appears only if Windows Authentication is selected in the Enable Authentication Methods section.
- Smart Card: This option enables smart card authentication.
- Select the number of client certificates to collect from the Number of Certificates pull-down list. The recommended value is 3.
- Optionally, in the Regular Expression field, enter a regular expression in the following format:
UID=(?<edipi>\d{8,10}). Contact BlackBerry AtHoc customer support to configure this field. - Optionally, in the Client Regular Expression field, enter a client regular expression in the following format:
.*?(^)(?:(?!\s-[A||E||S]).)*. This format extracts information from the client certificate subject name to find the identical certificates for authentication. The regular expression provided in the UI is a sample expression that may not be suitable for your environment. You can build you own regular expression or contact BlackBerry AtHoc customer support to configure this field. - Optionally, in the Custom Attributes field, add custom attributes to the CAC certificate. Add multiple attributes separated by a comma. There is a 100 character limit. The special characters < and > are not supported.
- Optionally, select Create new user if an account is not found to configure the desktop app to create a user at sign on if the user does not already exist.
- Defer to Self Service: This option requires users to sign in using a registration window determined by the authentication type configured for Self Service.
- If the Self Service authentication method is set to Username and Password, the users sees a registration window and must provide their first name, last name, username, password, confirm their password, and fill in a captcha. The user has the option to register as a new user or to sign in with their existing user credentials.
- If the Self Service authentication method is set to Smart Card, the user sees a CAC Certificate selection screen and must pick a certificate.
- If the Self Service authentication method is set to Windows Authentication, the user sees a Windows credentials screen and must provide their username and password.
- If the Self Service authentication method is set to Single Sign-On, the user is sent to a configured external URL for single sign-on.
- Windows Authentication: This option configures the desktop app to use only the Windows username or to use both the Windows username and the domain.
- LDAP Attribute: This option enables the desktop app to authenticate with an Active Directory attribute.
- If LDAP Attribute, Smart Card, or Windows Authentication is selected, you can select Create new user if an account is not found to configure the desktop app to create a user at sign on if the user does not already exist.
- Click Save.