Skip Navigation

Enable automatic authentication for
iOS
devices using a single sign-on profile

The single sign-on profile is a legacy profile with basic configuration options. If you want to use the more advanced single sign-on extension profile, see Enable automatic authentication for iOS devices using a single sign-on extension profile.
If you want to use certificate-based authentication, you must first create a shared certificate profile, SCEP profile, or user credential profile.
  1. In the management console, on the menu bar, click
    Policies and profiles > Networks and connections > Single sign-on
    .
  2. Click The Add icon.
  3. Type a name and description for the profile.
  4. In the
    Kerberos
    section, click The Add icon.
  5. In the
    Name
    field, type a name for the configuration.
  6. In the
    Principal name
    field, type the name of the
    Kerberos
    Principal, using the format
    <primary>/<instance>@<realm>
    (for example, user/admin@blackberry.example.com).
  7. In the
    Realm
    field, type the
    Kerberos
    realm in uppercase letters (for example, EXAMPLE.COM).
  8. In the
    URL prefixes
    field, type the URL prefix for the sites that you want devices to authenticate with. The prefix must begin with http:// or https://, and can include wildcard values (*) (for example, https://www.blackberry.example.com/*).
    If necessary, click The Add icon to add additional URL prefixes.
  9. If you want to limit the configuration to specific apps, click + beside
    App identifiers
    and specify the app bundle ID. You can use a wildcard value (*) to match the ID to multiple apps (for example, com.company.*).
    If necessary, click The Add icon to add additional URL prefixes.
  10. If you want
    iOS
    devices to use certificate-based authentication, in the
    Credentials
    drop-down list, click
    Certificate
    ,
    SCEP
    , or
    User credential
    . In the drop-down list, click the certificate profile that you want to use.
  11. Click
    Add
    .
  12. Click
    Add
    again.
  • If necessary, rank the profile.
  • Assign the profile to user accounts and groups.