---
title: Active Directory and Kerberos
description: You can configure PingFederate to authenticate users through the following identity provider (IdP) adapters or token processors.
component: pingfederate
version: 13.0
page_id: pingfederate:administrators_reference_guide:pf_active_directory_kerberos
canonical_url: https://docs.pingidentity.com/pingfederate/13.0/administrators_reference_guide/pf_active_directory_kerberos.html
revdate: August 3, 2022
---

# Active Directory and Kerberos

You can configure PingFederate to authenticate users through the following identity provider (IdP) adapters or token processors.

| Adapter or Token Processor                       | Description                                                                                                                                                                                                           |
| ------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| PingFederate integrated Kerberos Adapter         | Using the built-in Kerberos Adapter with a configured AD domain allows a PingFederate identity provider (IdP) server to perform single sign-on (SSO) to service provider (SP) applications based on Kerberos tickets. |
| PingFederate integrated Kerberos Token Processor | The built-in Kerberos Token Processor accepts and validates Kerberos tokens through a configured Kerberos Realm from a web service client.                                                                            |

|   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| - | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | As of version 10.3 and above, PingFederate no longer supports the IWA integration kit. You can find more information about Migrating from the IWA Integration Kit to the PingFederate Kerberos adapter in [Migrating from the Integrated Windows Authentication integration kit to the PingFederate Kerberos adapter](https://support.pingidentity.com/s/article/Migrating-from-the-Integrated-Windows-Authentication-integration-kit-to-the-PingFederate-Kerberos-adapter) in the Ping Identity Support Portal. |
