How To: Configure Integrated Windows Authentication with a Highly-Available Portal (2024)

Table of Contents
Summary Procedure FAQs

Summary

If an ArcGIS Web Adaptor (IIS)is installed behind a Network Load Balancer (NLB) to support a highly-available portal, it is necessary to perform additional configuration steps in IIS to ensure Integrated Windows Authentication works correctly with the deployment.

Procedure

If planningto use an ArcGIS Web Adaptor (IIS) for Integrated Windows Authentication with a highly-available portal, it is necessary to perform some complex configuration steps in IIS to ensure the Web Adaptor works correctly with the highly-available portal deployment. It is recommended to review the below configuration steps to ensure the organization can support Integrated Windows Authentication in IIS.

If the Web Adaptoris installed in front of the NLB or if web-tier authentication in IIS is not being used, skip this article.

Note: The first step below must be performed by a domain administrator. Review these instructions and coordinate with an administrator so they understand the requirements for configuring the ArcGIS Web Adaptor (IIS) with a highly-available portal.
  1. Request the domain administrator to create a new domain account and Service Principal Name (SPN), by using the commands below. The domain account name must match the host name of the NLB. Record the domain and name of the new account; this is needed in a subsequent step.
    setspn -A HTTP/NLBhostname.domain.com newaccountsetspn -A HTTP/NLBhostname newaccountsetspn -A HTTPS/NLBhostname.domain.com newaccountsetspn -A HTTPS/NLBhostname newaccount
  2. On the first portal machine hosting the Web Adaptor, open IIS Manager, expand the Server node in the Connections list, and click Application Pools.
  3. Right-click the ArcGISWebAdaptorAppPool and select Advanced Settings.
  4. Select the Identity property row, and click the ellipses button to open the Application Pool Identity window. Select the Custom account option and click Set… In the Set Credentials window, use the domain account created by the domain administrator (using the format domain\newaccount), and specify the password for the user. Click OK, click OK again, and click OKonce more to set the custom Application Pool Identity.
  5. Enable Windows Authentication for the website hosting the Web Adaptor. To do this, expand the Sites node under the Server node in the Connections panel andexpand the Web Site hosting the web adaptor node. Select the name for the Web Adaptor installed to IIS node. In the middle panel under the IIS section, double-click Authentication. In the Authentication panel, right-click Anonymous Authentication and select Disable. Right-click Windows Authentication and select Enable. Ensure only Windows Authentication is enabled.
  6. Right-click Windows Authentication and select Providers. Verify that Negotiate and NTLM are enabled, and click Cancel.
    1. If one or both of them are not listed, select it from the list of available providers and click Add.
  7. Right-click Windows Authentication and select Advanced Settings. Verify that Kernel-mode authentication is disabled, and click Cancel. If it is enabled, uncheck the check box next to the option.
  8. In the Connections list, click the Web Adaptor name to view its properties panel, and in the middle panel under the Management section, double-click Configuration Editor. From the Section drop-down list, expand the system.webServer node > the security node > the authentication node, and select windowsAuthentication.
  9. Set the useAppPoolCredentials property to True.
  10. In the Connections panel, select the web Server name, and in the Actions panel, click Restartto apply the changes.
  11. Close IIS Manager.
  12. Repeat steps 2-11 on the second Web Adaptor machine. When configuring the domain account to run the Web Adaptor application pool, specify the same domain account used in step 4.

If using Microsoft Internet Explorer to access the portal, add the organization-facing portal URL to the list of Local intranet web sites. For full instructions, consult the Internet Explorer product documentation.

Note:This applies to all versions of ArcGIS Enterprise portal 10.3 through 11.0.
How To: Configure Integrated Windows Authentication with a Highly-Available Portal (2024)

FAQs

How do I set up integrated Windows authentication? ›

Procedure
  1. Start the browser and open Internet options.
  2. Click the Advanced tab. In the Security section, select Enable Integrated Windows Authentication.

How do I configure my browser to use integrated Windows authentication? ›

Open the Windows Control Panel and go to Network and Internet > Internet Options. On the Advanced tab, select Enable Integrated Windows Authentication.

How to enable integrated Windows authentication in IIS? ›

From the IIS section of the center pane, open Authentication.
  1. Right-click on Windows Authentication and select Enable.
  2. If any other forms of authentication are enabled, right-click on those methods and disable them.

What is the difference between Windows Authentication and integrated Windows authentication? ›

Integrated Windows Authentication uses the security features of Windows clients and servers. Unlike Basic Authentication or Digest Authentication, initially, it does not prompt users for a user name and password.

Is integrated Windows authentication deprecated? ›

IWA (Integrated Windows Authentication) is considered a deprecated option for identity sources in vCenter Server. IWA uses Likewise to communicate with the AD domain, and so also uses Kerberos for authentication.

Is NTLM the same as Windows Authentication? ›

NTLM authentication is still supported and must be used for Windows authentication with systems configured as a member of a workgroup. NTLM authentication is also used for local logon authentication on non-domain controllers.

How do I change Windows Authentication in IIS? ›

On the IIS system, select Start -> Programs > Administrative Tools -> IIS Manager. Select Properties and select the Directory Security tab. Click the Edit button next to Enable anonymous access , and edit the authentication messages for this resource.

Is Windows Authentication the same as Kerberos? ›

Kerberos has been the default Windows authentication protocol since 2000, but there are still scenarios where it can't be used and where Windows falls back to NTLM.

How do I troubleshoot IIS Windows Authentication? ›

Resolution
  1. Disable the Web agent and restart IIS;
  2. Change the Internet Explorer logon setting from. ...
  3. Attempt to access http://FQDN/siteminderagent/ntlm/creds.ntc (Must. ...
  4. A prompt for credentials by IIS should show up;
  5. Provide credentials. ...
  6. If IIS Windows Authentication is configured correctly, a '404'
Jan 12, 2022

Which two authentication methods does integrated Windows authentication use to validate Windows credentials? ›

This method leverages protocols like NTLM (NT LAN Manager) or Kerberos to authenticate users without needing them to re-enter their credentials when accessing services or applications within the Windows domain.

How to enable Windows integrated authentication in Edge? ›

1. Enabling Integrated Windows Authentication on the browser
  1. Click the Windows Start menu and then “Control Panel.”
  2. Click "Internet Options."
  3. Click the “Security” tab.
  4. Click “Local intranet” and then “Custom level...”
  5. Select “User authentication > Logon > Automatic logon only in Intranet zone” and then click “o*k.”

How to enable Windows Authentication? ›

Enabling Windows authentication in IIS
  1. Go to Control Panel -> Programs and Features -> Turn windows features on or off.
  2. Expand Internet Information Services -> World Wide Web Services.
  3. Under Security, select the Windows Authentication check box.
  4. Click OK to finish the configuration.

How do I set up Windows authenticator? ›

Add Authenticator as a way to verify sign-in
  1. On your computer, go to Advanced security options in your Microsoft account dashboard. Sign in.
  2. Select Add a new way to sign in or verify.
  3. Choose Use an app. ...
  4. Open Authenticator on your phone and select the plus icon.
  5. Select Personal account then tap Scan a QR Code.

How do I connect to Windows Authentication? ›

On the taskbar, click Start, and then click Control Panel. In Control Panel, click Programs and Features, and then click Turn Windows Features on or off. Expand Internet Information Services, then World Wide Web Services, then Security. Select Windows Authentication, and then click OK.

What is the username and password for Windows Authentication? ›

The Username for Windows Authentication is basically the username of the remote device's local administrator account. It is very important that a local user account is set up on the remote computer (as highlighted in yellow). You can find it under Settings ➜ Accounts ➜ Other users.

Top Articles
How Long Can A Credit Card Charge Be Pending? | Bankrate
I had a death in my family. How do I recover their crypto?
Evil Dead Movies In Order & Timeline
Diario Las Americas Rentas Hialeah
Cold Air Intake - High-flow, Roto-mold Tube - TOYOTA TACOMA V6-4.0
Fully Enclosed IP20 Interface Modules To Ensure Safety In Industrial Environment
Victoria Secret Comenity Easy Pay
Tlc Africa Deaths 2021
CSC error CS0006: Metadata file 'SonarAnalyzer.dll' could not be found
PGA of America leaving Palm Beach Gardens for Frisco, Texas
Fredericksburg Free Lance Star Obituaries
The Murdoch succession drama kicks off this week. Here's everything you need to know
Michaels W2 Online
Gino Jennings Live Stream Today
Vrachtwagens in Nederland kopen - gebruikt en nieuw - TrucksNL
Bridge.trihealth
Craigslist Pinellas County Rentals
Moving Sales Craigslist
Putin advierte que si se permite a Ucrania usar misiles de largo alcance, los países de la OTAN estarán en guerra con Rusia - BBC News Mundo
How to Grow and Care for Four O'Clock Plants
27 Paul Rudd Memes to Get You Through the Week
Ihub Fnma Message Board
Panola County Busted Newspaper
Apparent assassination attempt | Suspect never had Trump in sight, did not get off shot: Officials
Synergy Grand Rapids Public Schools
Labcorp.leavepro.com
Schooology Fcps
Little Einsteins Transcript
Evil Dead Rise - Everything You Need To Know
+18886727547
134 Paige St. Owego Ny
Inmate Search Disclaimer – Sheriff
Learn4Good Job Posting
Bt33Nhn
Top-ranked Wisconsin beats Marquette in front of record volleyball crowd at Fiserv Forum. What we learned.
Is Arnold Swansinger Married
ENDOCRINOLOGY-PSR in Lewes, DE for Beebe Healthcare
Jail View Sumter
Stanley Steemer Johnson City Tn
Gfs Ordering Online
Barstool Sports Gif
11 Best Hotels in Cologne (Köln), Germany in 2024 - My Germany Vacation
Southwest Airlines Departures Atlanta
Scythe Banned Combos
Enr 2100
Sandra Sancc
Booknet.com Contract Marriage 2
Headlining Hip Hopper Crossword Clue
5103 Liberty Ave, North Bergen, NJ 07047 - MLS 240018284 - Coldwell Banker
Hy-Vee, Inc. hiring Market Grille Express Assistant Department Manager in New Hope, MN | LinkedIn
Escape From Tarkov Supply Plans Therapist Quest Guide
Latest Posts
Article information

Author: Maia Crooks Jr

Last Updated:

Views: 5918

Rating: 4.2 / 5 (43 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Maia Crooks Jr

Birthday: 1997-09-21

Address: 93119 Joseph Street, Peggyfurt, NC 11582

Phone: +2983088926881

Job: Principal Design Liaison

Hobby: Web surfing, Skiing, role-playing games, Sketching, Polo, Sewing, Genealogy

Introduction: My name is Maia Crooks Jr, I am a homely, joyous, shiny, successful, hilarious, thoughtful, joyous person who loves writing and wants to share my knowledge and understanding with you.