To configure Internet Explorer for Kerberos authentication, review the following settings in Internet Options.
-
Add the base URL to Local intranet.
Note:
This step may be skipped if the base URL (<pf-idp.domain.name>) is internal and not fully qualified. For example, if it is
pingfederate
, you can skip this step. However, if <pf-idp.domain.name> iswww.example.com
, then you must add the base URL to the Sites list, as described in the following sub steps.- Close all Internet Explorer tabs and windows.
- Open Control Panel > Internet Options.
- Click the Security tab.
- Select Local intranet and click Sites.
- Click Advanced.
-
Enter the base URL (for example,
www.example.com
), and then click Add. - Click Close, and then click OK to return to the Security tab.
-
Verify Automatic logon only in the Intranet zone is
selected.
- Under the Security tab, select Local intranet and click Custom level.
- Verify Automatic logon only in the Intranet zone is selected in the Settings pane.
- Click OK to return to the Security tab.
-
Verify proxy settings.
Note:
Skip the following sub steps if a proxy is not used.
- Click the Connections tab.
- Click LAN settings.
- Verify the Use a proxy server for your LAN ... check box is selected, and then click Advanced.
- Enter the base URL in the Exceptions field, and then click OK.
- Click OK to return to the Connections tab.
-
Verify Enable Integrated Windows Authentication is
selected.
- Click the Advanced tab.
- Verify Enable Integrated Windows Authentication is selected in the Settings pane.
- Click OK to close Internet Options.