---
title: Enabling Kerberos authentication
description: You can enable Kerberos authentication to provide end users with a seamless sign-on experience if the Microsoft 365 users are migrated into PingOne from AD through the LDAP Gateway and if your Microsoft 365 applications support the Active Profile sign-in option.
component: pingone
page_id: pingone:applications:p1_enabling_kerberos_authentication
canonical_url: https://docs.pingidentity.com/pingone/applications/p1_enabling_kerberos_authentication.html
revdate: November 6, 2023
section_ids:
  before-you-begin: Before you begin
  steps: Steps
---

# Enabling Kerberos authentication

You can enable Kerberos authentication to provide end users with a seamless sign-on experience if the Microsoft 365 users are migrated into PingOne from Active Directory (AD) *(tooltip: \<div class="paragraph">
\<p>A directory service for Windows domain networks, included in most Windows Server operation systems.\</p>
\</div>)* through the LDAP Gateway and if your Microsoft 365 applications support the Active Profile sign-in option.

## Before you begin

You must have:

* An [LDAP Gateway](../integrations/p1_ldap_gateways.html) configuration with [Kerberos authentication](../integrations/p1_kerberos_authentication.html) enabled

* At least one [user type](../integrations/p1_add_a_user_type.html) configured

* A configured [SPN](../integrations/p1_creating_spns.html) in AD

* An LDAP Gateway deployed in the network where it can reach the targeted domain controllers

## Steps

1. In the PingOne admin console, go to **Applications > Applications** and click the **Microsoft 365 application** in the **Applications** list.

2. If you haven't already, click **Enable Advanced Configuration** on the **Overview** tab and click **Enable** in the confirmation modal.

   ![A screenshot of Enable Advanced Configuration button on the Overview tab.](_images/p1-microsoft-365-application-enable-advanced-configuration.png)

3. On the **Configuration** tab, click the **Pencil** icon ([icon: pencil, set=fa]).

4. Select the **Enable Kerberos Authentication** checkbox.

5. Click **[icon: plus, set=fa]Add Gateway User Type**.

6. Select a **Gateway** and a **User Type**.

7. Click **Save**.
