<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP/IWA issues in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314867#M12047</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV data-reddit-rtjson="{&amp;quot;entityMap&amp;quot;:{},&amp;quot;blocks&amp;quot;:[{&amp;quot;key&amp;quot;:&amp;quot;7emt&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;Hello All!&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;9k9rb&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;I'm looking for some help with my Windows Authentication to ArcGIS Enterprise Portal (we are using 10.6.1 at this time). We have to put our network's domain in the username portion to get the account to authenticate with Active Directory (example: networkdomain/amcsparran or amcsparran@networkdomain). Does anyone found a way that if a user from my company just types the username (\&amp;quot;amcsparran\&amp;quot; in this case) it will automatically default to the Active Directory domain? The goal is for users to just have to put in username and password without the domain.&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;6j3mv&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;Also, we've tried the LDAP route which would make this possible, but have had issues with getting it up and running...&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;v88v&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;5lf14&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;Any ideas would be fantastic!&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}}]}"&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="60a016_initial-0-0"&gt;&lt;DIV class="" data-offset-key="60a016_initial-0-0"&gt;&lt;SPAN data-offset-key="60a016_initial-0-0"&gt;&lt;SPAN data-text="true"&gt;Hello All!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="79hir-0-0"&gt;&lt;DIV class="" data-offset-key="79hir-0-0"&gt;&lt;SPAN data-offset-key="79hir-0-0"&gt;&lt;SPAN data-text="true"&gt;I'm looking for some help with my Windows Authentication to ArcGIS Enterprise Portal (we are using 10.6.1 at this time). &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" data-offset-key="79hir-0-0"&gt;&lt;SPAN data-offset-key="79hir-0-0"&gt;&lt;SPAN data-text="true"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" data-offset-key="79hir-0-0"&gt;&lt;SPAN data-offset-key="79hir-0-0"&gt;&lt;SPAN data-text="true"&gt;We are currently configured for IWA, but have to put our network's domain in the username portion to get the account to authenticate with Active Directory (example: networkdomain/amcsparran or amcsparran@networkdomain). Does anyone know a way that if a user from my company just types the username ("amcsparran" in this case) it will automatically default to the Active Directory domain? The goal is for users to just have to put in username and password without the domain.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="fpo3u-0-0"&gt;&lt;DIV class="" data-offset-key="fpo3u-0-0"&gt;&lt;SPAN data-offset-key="fpo3u-0-0"&gt;&lt;SPAN data-text="true"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" data-offset-key="fpo3u-0-0"&gt;&lt;SPAN data-offset-key="fpo3u-0-0"&gt;&lt;SPAN data-text="true"&gt;Also, we've tried the LDAP route which would make this possible, but have had issues with getting it up and running...so any help in that arena would be helpful also, but my understanding is we may need a Java Web Adaptor for that to work, and right now we are running with an IIS web adaptor.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="fl79e-0-0"&gt;&lt;DIV class="" data-offset-key="fl79e-0-0"&gt;&lt;SPAN data-offset-key="fl79e-0-0"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="b25tk-0-0"&gt;&lt;DIV class="" data-offset-key="b25tk-0-0"&gt;&lt;SPAN data-offset-key="b25tk-0-0"&gt;&lt;SPAN data-text="true"&gt;Any ideas would be fantastic!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 May 2019 18:30:57 GMT</pubDate>
    <dc:creator>AdamMcSparran</dc:creator>
    <dc:date>2019-05-30T18:30:57Z</dc:date>
    <item>
      <title>LDAP/IWA issues</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314867#M12047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV data-reddit-rtjson="{&amp;quot;entityMap&amp;quot;:{},&amp;quot;blocks&amp;quot;:[{&amp;quot;key&amp;quot;:&amp;quot;7emt&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;Hello All!&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;9k9rb&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;I'm looking for some help with my Windows Authentication to ArcGIS Enterprise Portal (we are using 10.6.1 at this time). We have to put our network's domain in the username portion to get the account to authenticate with Active Directory (example: networkdomain/amcsparran or amcsparran@networkdomain). Does anyone found a way that if a user from my company just types the username (\&amp;quot;amcsparran\&amp;quot; in this case) it will automatically default to the Active Directory domain? The goal is for users to just have to put in username and password without the domain.&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;6j3mv&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;Also, we've tried the LDAP route which would make this possible, but have had issues with getting it up and running...&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;v88v&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;5lf14&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;Any ideas would be fantastic!&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}}]}"&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="60a016_initial-0-0"&gt;&lt;DIV class="" data-offset-key="60a016_initial-0-0"&gt;&lt;SPAN data-offset-key="60a016_initial-0-0"&gt;&lt;SPAN data-text="true"&gt;Hello All!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="79hir-0-0"&gt;&lt;DIV class="" data-offset-key="79hir-0-0"&gt;&lt;SPAN data-offset-key="79hir-0-0"&gt;&lt;SPAN data-text="true"&gt;I'm looking for some help with my Windows Authentication to ArcGIS Enterprise Portal (we are using 10.6.1 at this time). &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" data-offset-key="79hir-0-0"&gt;&lt;SPAN data-offset-key="79hir-0-0"&gt;&lt;SPAN data-text="true"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" data-offset-key="79hir-0-0"&gt;&lt;SPAN data-offset-key="79hir-0-0"&gt;&lt;SPAN data-text="true"&gt;We are currently configured for IWA, but have to put our network's domain in the username portion to get the account to authenticate with Active Directory (example: networkdomain/amcsparran or amcsparran@networkdomain). Does anyone know a way that if a user from my company just types the username ("amcsparran" in this case) it will automatically default to the Active Directory domain? The goal is for users to just have to put in username and password without the domain.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="fpo3u-0-0"&gt;&lt;DIV class="" data-offset-key="fpo3u-0-0"&gt;&lt;SPAN data-offset-key="fpo3u-0-0"&gt;&lt;SPAN data-text="true"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" data-offset-key="fpo3u-0-0"&gt;&lt;SPAN data-offset-key="fpo3u-0-0"&gt;&lt;SPAN data-text="true"&gt;Also, we've tried the LDAP route which would make this possible, but have had issues with getting it up and running...so any help in that arena would be helpful also, but my understanding is we may need a Java Web Adaptor for that to work, and right now we are running with an IIS web adaptor.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="fl79e-0-0"&gt;&lt;DIV class="" data-offset-key="fl79e-0-0"&gt;&lt;SPAN data-offset-key="fl79e-0-0"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="" data-block="true" data-editor="60a016" data-offset-key="b25tk-0-0"&gt;&lt;DIV class="" data-offset-key="b25tk-0-0"&gt;&lt;SPAN data-offset-key="b25tk-0-0"&gt;&lt;SPAN data-text="true"&gt;Any ideas would be fantastic!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2019 18:30:57 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314867#M12047</guid>
      <dc:creator>AdamMcSparran</dc:creator>
      <dc:date>2019-05-30T18:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP/IWA issues</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314868#M12048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your portal exposed to the outside, or just internal/VPN users? If just internal/VPN, I'd personally push out a GPO to add your portal to the list of trusted sites in IE. That way you&amp;nbsp;should get a single signon experience and won't need to manually pass credentials at all, as long as you're logged into the domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2019 19:52:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314868#M12048</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2019-05-30T19:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP/IWA issues</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314869#M12049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Randall,&lt;/P&gt;&lt;P&gt;It is open to the outside. I only want users who are on our domain to access Portal, but I want some of my applications and layers to be open to everyone (for say an Open Data Portal). I've been looking at the SAML single sign on option, but I thought I had read somewhere that I cannot use built-in logins as well as SAML. I have Field Workers who are not in Active Directory that use applications in the field, and I want them to be able to access as well. Not to mention we have public facing applications in the works as well. If I can do all that with SAML, then I'm in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2019 19:57:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314869#M12049</guid>
      <dc:creator>AdamMcSparran</dc:creator>
      <dc:date>2019-05-30T19:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP/IWA issues</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314870#M12050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd strongly recommend SAML over IWA in a situation where you need to share some services to the public but keep others private. You can support both built in and domain users with SAML, but not with IWA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAML is by far your best option here. You can even support multi-factor auth with Portal if your SAML provider can support it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2019 20:22:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314870#M12050</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2019-05-30T20:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP/IWA issues</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314871#M12051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome! Apparently I've gotten some bad information in the past. Going to go forward with SAML.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Randall!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2019 20:41:06 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/ldap-iwa-issues/m-p/314871#M12051</guid>
      <dc:creator>AdamMcSparran</dc:creator>
      <dc:date>2019-05-30T20:41:06Z</dc:date>
    </item>
  </channel>
</rss>

