---
title: IWA Integration
description: Integrated Windows Authentication (IWA) is a process that allows users to authenticate with Windows credentials using the Kerberos or (legacy) NTLM protocols.
component: pingaccess
version: 8.1
page_id: pingaccess:agents_and_integrations:pa_iwa_integration
canonical_url: https://docs.pingidentity.com/pingaccess/9.1/agents_and_integrations/pa_iwa_integration.html
llms_txt: https://docs.pingidentity.com/pingaccess/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: February 6, 2023
superseded_by: https://docs.pingidentity.com/pingaccess/9.1/agents_and_integrations/pa_iwa_integration.html
section_ids:
  setting-up-iwa-using-pingfederate: Setting up IWA using PingFederate
  about-this-task: About this task
  steps: Steps
  result: Result:
  setting-up-iwa-directly: Setting up IWA directly
  about-this-task-2: About this task
  steps-2: Steps
  result-2: Result:
---

# IWA Integration

Integrated Windows Authentication (IWA) is a process that allows users to authenticate with Windows credentials using the Kerberos or (legacy) NTLM protocols.

Unlike session-based authentication, IWA relies on authenticating client-server connections, which are then given access to protected content. PingAccess handles these connections differently, although configuration in the Admin UI is identical to normal applications. This document is intended to clarify IWA connection handling in PingAccess and help administrators avoid common mistakes in this configuration.

|   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| - | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | For IWA to work, every node in the network architecture must support bound connections, including load balancers, gateways, and proxies. If a network component in front of PingAccess improperly re-uses an authenticated connection, PingAccess might break this connection to prevent session stealing.The AWS ELB does not support IWA.NTLM is no longer supported in PingFederate, however NTLM connections are treated the same as Kerberos connections in PingAccess. |

## Setting up IWA using PingFederate

### About this task

Set up an application to be protected with Kerberos authentication using PingFederate's Kerberos Adapter, while PingFederate is protected by PingAccess:

### Steps

1. Configure your Kerberos adapter in PingFederate.

   For more information, see [Configure a Kerberos adapter instance](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_config_kerberos_adapt_instance.html) in the PingFederate documentation.

2. Add a new site in PingAccess.

   1. Go to **Applications → Sites** and click **[icon: plus, set=fa]Add Site**.

   2. In the **Name** field, enter a desired name for the site.

   3. In the **Targets** field, enter one or more hostname:port pairs for the site.

      The host and port to point to PingFederate on port `9031`.

   4. Click **Save**.

   For more information, see [Adding sites](../pingaccess_user_interface_reference_guide/pa_adding_sites.html).

3. Add a new application in PingAccess.

   1. Go to **Applications → Applications** and click **[icon: plus, set=fa]Add Application**.

   2. In the **Name** field, enter a desired name for the site.

   3. In the **Context Root** field, specify the first part of the URL path for the application and its resources.

   4. In the **Virtual Host** field, enter the host desired for the target application.

   5. In the **Destination** list, select **Site**.

   6. In the **Site** list, select the PingFederate site previously created.

   7. Configure the remaining fields as desired. Click **Save**.

   For more information, see [Adding an application](../pingaccess_user_interface_reference_guide/pa_adding_an_app.html).

4. Enable the application.

   #### Result:

   The protected application can utilize the Kerberos protocol for authentication through PingAccess, using PingFederate.

## Setting up IWA directly

### About this task

Set up PingAccess to manage an application that already uses IWA for authentication.

### Steps

1. Add a new site in PingAccess.

   1. Go to **Applications → Sites** and click **[icon: plus, set=fa]Add Site**.

   2. In the **Name** field, enter a desired name for the site.

   3. In the **Targets** field, enter one or more hostname:port pairs for the site.

   4. Click **Save**.

   For more information, see [Adding sites](../pingaccess_user_interface_reference_guide/pa_adding_sites.html).

2. Add a new Application in PingAccess.

   1. Go to **Applications → Applications** and click **[icon: plus, set=fa]Add Application**.

   2. In the **Name** field, enter a desired name for the site.

   3. In the **Context Root** field, specify the first part of the URL path for the application and its resources.

   4. In the **Virtual Host** field, enter the host desired for the target application.

   5. In the **Destination** list, select **Site**.

   6. In the **Site** list, select the site for this application.

   7. Configure the remaining fields as desired. Click **Save**.

   For more information, see [Adding an application](../pingaccess_user_interface_reference_guide/pa_adding_an_app.html).

3. Enable the application.

   #### Result:

   The protected application can utilize the Kerberos protocol for authentication through PingAccess.
