How to configure single-sign-on for ArcGIS Enterprise base deployment ?

1795
21
11-12-2021 06:18 AM
JohnHu
by
New Contributor III

I just installed and configured ArcGIS Enterprise 10.9 base deployment and also integrated window authentication with my organization's Active Directory.  I can add portal user from our Active Directory and use regular window user account.  The problem is that single-sign-on is not working,  and I have enter my window username and pwd to login into portal.  I like to get help on how to get single-sign-on to work for our ArcGIS portal.  Thanks in advance for your help.

0 Kudos
21 Replies
ReeseFacendini
Esri Contributor

To enable single-sign-on via IWA (Active Directory accounts), open up IIS on the machine where the Portal for ArcGIS web adaptor is installed.  Expand the connections list, until you see the web adaptor for Portal, listed under Default Web Site.  Looking at the options, go into authentication (under the IIS grouping), and disable Anonymous Authentication then enable Windows Authentication.  See this link for more details

0 Kudos
JohnHu
by
New Contributor III

ReeseFacendini,  Thanks for your response.  I followed steps listed in your link (Esri online reference) and already done all steps including above configuration for portal web adapter.  But single-sign-on is still not working,  show the portal sign in page,  and I have to put my window login and pwd to get into portal.

0 Kudos
ReeseFacendini
Esri Contributor

Try clearing your browser's cache, then loading the Portal home page again.  

0 Kudos
JohnHu
by
New Contributor III

This was done already as part of the troubleshooting process.  My main question is that anything else I need to do or configure other than the steps mentioned in above Esri link for setting up integrated window authentication for portal.   Thanks.

0 Kudos
ReeseFacendini
Esri Contributor

There are no additional steps, outside of the ones outlined in the document linked above.  Other than clearing browser cache for at least the last month, the only other steps I can recommend are opening a private / incognito window to see if the page signs you in, or try a different browser than the one you are currently using.

0 Kudos
BillFox
MVP Frequent Contributor

are you looking to use ADFS?

0 Kudos
JohnHu
by
New Contributor III

Bill, not yet.  I am trying to get single sign on to work with IWA and our Active Directory.

0 Kudos
BillFox
MVP Frequent Contributor

is this a federated setup?

0 Kudos
JohnHu
by
New Contributor III

Yes.  This is a 10.9 federated setup for ArcGIS Enterprise base deployment.  Single server install with portal, hosting arcgis server, and datastore - all on one server and federated

 

0 Kudos