AD SSO troubleshooting steps

AD SSO troubleshooting steps

Steps to configure SSO for different browsers:


Steps for IE, Chrome, Edge & Opera


1. Through 'Run' command, execute 'inetcpl.cpl'. Internet Properties will be

displayed.

2. Select the 'Security' tab in the pop-up window.

3. Choose the option 'Local Intranet' and click 'Sites' in the ‘Internet Properties’

dialog.

4. Add the PMP/PAM360/AMP server name alone.

5. Apply the changes.


Steps for Firefox


1. Open Firefox and type 'about:config' in the address bar, and then press Enter.

2. Accept the warning message to enter the configuration panel.

3. Search for 'network.automatic-ntlm-auth.trusted-uris' in the browser,

right-click it, and then select 'Modify'.

4. A dialog will be displayed. This dialog shows a list of application URLs (comma

separated) to the users, which will be logged on to the application automatically.

5. Include the PMP/PAM360/AMP server name in this list.


If you want to push the SSO related configuration on multiple machines through GPO:


1. Connect to the domain controller and create a new group policy named

'Settings – Intranet Zones'. Group Policy Management(gpmc.msc).

2. Right-click the policy and select Edit.

3. Expand Computer Configuration > Policies > Administrative Templates >

Windows Components > Internet Explorer > Internet Control Panel. When you click

Security Page, the available settings would appear on the right pane.

4. Right-click Site to Zone Assignment List and select "Edit" to modify its settings.

5. Select Enabled.

6. In the Options pane, click the Show button.

7. Type the Value name of the trusted intranet site: Specify PMP\PAM360\AMP server name in this list.

8. Enter the Value for which zone this trusted intranet site should be associated

with: 1

9. Click OK to close the Site to Zone Assignment List settings box.

10. Delegate GPO to the required computers.

                  New to ADSelfService Plus?

                    • Related Articles

                    • Importing Users from AD

                      Check if PAM360 is installed in a member server or a workgroup machine. Member servers will by default have connectivity to AD and if it is a workgroup machine then there should be a connectivity available from workgroup machine to primary domain ...
                    • Importing Users from LDAP

                      Generally LDAP option is used only if the customer has PAM360 installed on a Linux server. Check with the customer for the reason for installing PAM360 on a Linux server and inform them that they will have to install the Agents on ALL windows ...