Enable automatic authentication for iOS devices using a single sign-on profile

The single sign-on profile is a legacy profile with basic configuration options. If you want to use the more advanced single sign-on extension profile, see Enable automatic authentication for iOS devices using a single sign-on extension profile.
If you want to use certificate-based authentication, you must first create a shared certificate profile, SCEP profile, or user credential profile.
  1. In the management console, on the menu bar, click Policies and profiles > Networks and connections > Single sign-on.
  2. Click The Add icon.
  3. Type a name and description for the profile.
  4. In the Kerberos section, click The Add icon.
  5. In the Name field, type a name for the configuration.
  6. In the Principal name field, type the name of the Kerberos Principal, using the format <primary>/<instance>@<realm> (for example, user/admin@blackberry.example.com).
  7. In the Realm field, type the Kerberos realm in uppercase letters (for example, EXAMPLE.COM).
  8. In the URL prefixes field, type the URL prefix for the sites that you want devices to authenticate with. The prefix must begin with http:// or https://, and can include wildcard values (*) (for example, https://www.blackberry.example.com/*).
    If necessary, click The Add icon to add additional URL prefixes.
  9. If you want to limit the configuration to specific apps, click + beside App identifiers and specify the app bundle ID. You can use a wildcard value (*) to match the ID to multiple apps (for example, com.company.*).
    If necessary, click The Add icon to add additional URL prefixes.
  10. If you want iOS devices to use certificate-based authentication, in the Credentials drop-down list, click Certificate, SCEP, or User credential. In the drop-down list, click the certificate profile that you want to use.
  11. Click Add.
  12. Click Add again.
  • If necessary, rank the profile.
  • Assign the profile to user accounts and groups.