PingFederate Server

Active Directory and Kerberos

You can configure PingFederate to authenticate users through the following identity provider (IdP) adapters or token processors.

Adapter or Token Processor Description

PingFederate integrated Kerberos Adapter

Using the built-in Kerberos Adapter with a configured AD domain allows a PingFederate identity provider (IdP) server to perform single sign-on (SSO) to service provider (SP) applications based on Kerberos tickets.

PingFederate integrated Kerberos Token Processor

The built-in Kerberos Token Processor accepts and validates Kerberos tokens through a configured Kerberos Realm from a web service client.

As of version 10.3 and above, PingFederate no longer supports the IWA integration kit. For more information about Migrating from the IWA Integration Kit to the PingFederate Kerberos adapter, see https://support.pingidentity.com/s/article/Migrating-from-the-Integrated-Windows-Authentication-integration-kit-to-the-PingFederate-Kerberos-adapter in the Ping Identity Support Portal.