Home

Authentication single sign on

%3CLINGO-SUB%20id%3D%22lingo-sub-188305%22%20slang%3D%22en-US%22%3EAuthentication%20single%20sign%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-188305%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%3CP%3EDoes%20anyone%20know%20how%20to%20get%20WAC%20not%20to%20prompt%20for%20new%20credentials%2C%20and%20to%20use%20credentials%20that%20you%20are%20signed%20in%20with%3F%3C%2FP%3E%3CP%3EThe%20documentation%20on%20single%20sign%20on%20only%20covers%202012%20Domain%20Controllers%2C%20and%20we%20have%20a%202008r2%20domain%20controller.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Fconfigure%2Fuser-access-control%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Fconfigure%2Fuser-access-control%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-191394%22%20slang%3D%22en-US%22%3ERe%3A%20Authentication%20single%20sign%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-191394%22%20slang%3D%22en-US%22%3EHi.%3CBR%20%2F%3EI%20understand%20that's%20for%20Scom.%20Conceptually%20it%20should%20be%20a%20similar%20process%20for%20WAC%20I%20would%20have%20thought%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI%20will%20post%20feedback%20for%20this%3CBR%20%2F%3EThanks%3CBR%20%2F%3EDarren%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-191372%22%20slang%3D%22en-US%22%3ERe%3A%20Authentication%20single%20sign%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-191372%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Darren%2C%3C%2FP%3E%3CP%3EAs%20far%20as%20I%20know%2C%20SSO%20for%20different%20products%20is%20different.%3C%2FP%3E%3CP%3EThe%20link%20you%20have%20posted%20is%20for%20SCOM.%20So%20I%20am%20afraid%20it%20is%20not%20applicable%20to%20Window%20admin%20center.%3C%2FP%3E%3CP%3EAccording%20to%20official%20article%2C%20we%20need%20Server%202012%20DC%20to%20configure%20SSO%20for%20Windows%20Admin%20Center.%3C%2FP%3E%3CP%3EAnyway%2C%20we%20could%20submit%20a%20feedback%20to%20the%20following%20site.%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwindowsserver.uservoice.com%2Fforums%2F295071%2Fcategory%2F319162%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwindowsserver.uservoice.com%2Fforums%2F295071%2Fcategory%2F319162%3C%2FA%3E%3C%2FP%3E%3CP%3EBest%20regards%2C%3CBR%20%2F%3EMeipo%20Xu.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-191307%22%20slang%3D%22en-US%22%3ERe%3A%20Authentication%20single%20sign%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-191307%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20use%20an%20application%20called%20SquaredUp%20to%20visualize%20our%20SCOM%20data.%26nbsp%3B%20That%20server%20requires%20constrained%20delegation.%20They%20have%20an%20article%20on%20it.%26nbsp%3B%20That's%20probably%20the%20easiest%20thing%20to%20link%20to%2C%20rather%20than%20re-writing%20it.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftickets.squaredup.com%2Fsupport%2Fsolutions%2Farticles%2F208270-how-to-set-up-single-sign-on-using-kerberos-constrained-delegation%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftickets.squaredup.com%2Fsupport%2Fsolutions%2Farticles%2F208270-how-to-set-up-single-sign-on-using-kerberos-constrained-delegation%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20that%20help%3F%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3EDarren%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-190410%22%20slang%3D%22en-US%22%3ERe%3A%20Authentication%20single%20sign%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-190410%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Darren%2C%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EAccording%20to%20the%20explanation%20of%20that%20article%2C%20the%20prerequisite%20for%20configuring%20sso%20is%20server%202012DC.%3C%2FP%3E%3CP%3E%3CEM%3E%22(Be%20aware%20that%20this%20requires%20a%20domain%20controller%20running%20Windows%20Server%202012%20or%20later).%22%3C%2FEM%3E%3C%2FP%3E%3CP%3EI%20made%20more%20research%20on%20this%20and%20test%20on%20this%20in%20my%20own%20environment.%20I%20found%20the%20%22set-adcomputer%22%20option%20is%20only%20available%20for%20Server%202012.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fes-es%2Flibrary%2Fhh852268(v%3Dwps.620).aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fes-es%2Flibrary%2Fhh852268(v%3Dwps.620).aspx%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20I%20am%20curious%20to%20know%20how%20did%20you%20configure%20the%20constrained%20delegation%20with%202008%20domain%20controllers%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%2C%3CBR%20%2F%3EMeipo%20Xu.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-190352%22%20slang%3D%22en-US%22%3ERe%3A%20Authentication%20single%20sign%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-190352%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Meipo%3C%2FP%3E%3CP%3EI'm%20only%20managing%202012%20r2%20and%20above%2C%20so%20I'm%20meeting%20requirements.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20the%20Single%20Sign%20On%20with%20constrained%20delegation%20with%20a%202008%20DC%20I'm%20trying%20to%20get%20working%2C%20not%20manage%20a%202008%20DC.%3C%2FP%3E%3CP%3EThe%20documentation%20only%20covers%202012%20servers%2C%20but%20you%20can%20do%20constrained%20delegation%20%26nbsp%3Bwith%202008%20domain%20controllers.%26nbsp%3B%20I've%20set%20this%20up%2C%20but%20unable%20to%20get%20WAC%20to%20use%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-190334%22%20slang%3D%22en-US%22%3ERe%3A%20Authentication%20single%20sign%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-190334%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Darren%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20present%2C%20the%20windows%20admin%20center%20only%20support%20Windows%20Server%202012%20or%202012%20R2%20(with%20Windows%20Management%20Framework%205.1)%20and%20later%20version.%3C%2FP%3E%3CP%3EHere%20is%20a%20link%20for%20reference%20(%20Pay%20attention%20to%20%22Are%20there%20any%20other%20dependencies%20or%20prerequisites%3F%22%20and%20%22Are%20there%20any%20plans%20for%20Windows%20Admin%20Center%20to%20manage%20Windows%20Server%202008%20R2%20or%20earlier%3F%22parts%20%3A(%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Funderstand%2Ffaq%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Funderstand%2Ffaq%3C%2FA%3E%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EIn%20addtion%2C%20we%20could%20get%20the%20information%20that%20we%20need%20the%20server%20202%20and%20later%20version%20domain%20controller%20for%20the%20SSO%20from%20the%20link%20as%20you%20posted%20here.%3CBR%20%2F%3E%3CEM%3E%22(Be%20aware%20that%20this%20requires%20a%20domain%20controller%20running%20Windows%20Server%202012%20or%20later).%22%3C%2FEM%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%2C%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EMeipo%20Xu.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

Hi

Does anyone know how to get WAC not to prompt for new credentials, and to use credentials that you are signed in with?

The documentation on single sign on only covers 2012 Domain Controllers, and we have a 2008r2 domain controller.

https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-co...

 

6 Replies

Hi Darren,

 

At present, the windows admin center only support Windows Server 2012 or 2012 R2 (with Windows Management Framework 5.1) and later version.

Here is a link for reference ( Pay attention to "Are there any other dependencies or prerequisites?" and "Are there any plans for Windows Admin Center to manage Windows Server 2008 R2 or earlier?"parts :(

https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/understand/faq


In addtion, we could get the information that we need the server 202 and later version domain controller for the SSO from the link as you posted here.
"(Be aware that this requires a domain controller running Windows Server 2012 or later)."

 

Best regards,


Meipo Xu.

Hi Meipo

I'm only managing 2012 r2 and above, so I'm meeting requirements.

 

It's the Single Sign On with constrained delegation with a 2008 DC I'm trying to get working, not manage a 2008 DC.

The documentation only covers 2012 servers, but you can do constrained delegation  with 2008 domain controllers.  I've set this up, but unable to get WAC to use it.

 

 

 

Hi Darren,


According to the explanation of that article, the prerequisite for configuring sso is server 2012DC.

"(Be aware that this requires a domain controller running Windows Server 2012 or later)."

I made more research on this and test on this in my own environment. I found the "set-adcomputer" option is only available for Server 2012.

https://technet.microsoft.com/es-es/library/hh852268(v=wps.620).aspx

 

So I am curious to know how did you configure the constrained delegation with 2008 domain controllers?

 

Best regards,
Meipo Xu.

We use an application called SquaredUp to visualize our SCOM data.  That server requires constrained delegation. They have an article on it.  That's probably the easiest thing to link to, rather than re-writing it. 

 

https://tickets.squaredup.com/support/solutions/articles/208270-how-to-set-up-single-sign-on-using-k...

 

Does that help? 

Thanks

Darren

 

Hi Darren,

As far as I know, SSO for different products is different.

The link you have posted is for SCOM. So I am afraid it is not applicable to Window admin center.

According to official article, we need Server 2012 DC to configure SSO for Windows Admin Center.

Anyway, we could submit a feedback to the following site.
https://windowsserver.uservoice.com/forums/295071/category/319162

Best regards,
Meipo Xu.

Hi.
I understand that's for Scom. Conceptually it should be a similar process for WAC I would have thought?

I will post feedback for this
Thanks
Darren