Forum Discussion
SSO with Salesforce using Big-IP APM
Current configuration: Big-IP APM is configured as an IDP to control access and SSO into Salesforce.
Could Big-IP APM be configured to recognize a user's login into Windows (Active Directory)?
The requirement is to access Salesforce without being prompted for an id and password after logging into the enterprise network.
Please let me know if this is possible.
Thanks.
1 Reply
Yes, this should be possible. You would need to use a Kerberos AAA config to authenticate users that are using domain-attached workstations or laptops. This is one guide that describes the process: https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-authentication-single-sign-on-11-6-0/9.htmlconceptid
Depending on your access requirements, you may wish to use a separate VS for "internal" users if you are running any other services for external use. The Kerberos process can fall back on HTTP Basic authentication, but to me, that looks a tad ugly if I can use a Logon page instead.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com