SAMLWindowsSSO
Use to leverage the authentication already done on the windows workstation.
Please make sure that a SAMLDatasave authenticator is placed in front of this authenticator.
Properties
Example Configuration
{
"alias": "samlwin",
"name": "SAMLWindowsSSO",
"configuration": {
"idpID": "phenixid.ninja",
"pipeID": "authPipe1",
"iwaSSOTarget": "/saml/authenticate/samlwin",
},
"id": "samlwin"
}
Requirements
PAS must be installed on a windows host belonging to the same domain as the clients used by the users.
This authenticator MUST be used together with a SAMLDatasave authenticator.
Number of group membership restrictions
Users with a large number of group memberships may encounter problems with Kerberos authentication. Please view this article for more information: https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/kerberos-authentication-problems-if-user-belongs-to-groups