Forum Discussion
Josiah_39459
Apr 11, 2016Historic F5 Account
Since the LDAP auth applies only to the Access Policy, it has no bearing on the backend server. It sounds to me like your problem is likely in the SSO.
You didn't say what type of SSO you are using, but if it is expecting the samaccountname and you are sending the UPN and they are different, it's obviously going to fail, right?
- BigFootApr 11, 2016NimbostratusYes, I am using NTLMv1, sorry forgot to add here. and setting is default.Just domain is different. According to application team, they cannot see any authentication attemp on ADFS
- Josiah_39459Apr 11, 2016Historic F5 AccountWell, a packet capture and websso logs (potentially debug) will tell you for sure. NTLM's just a http header. But it seems as a bare minimum you have to fix your SSO credential assign to be valid.
- BigFootApr 21, 2016NimbostratusIt takes some time, but I did packet capture, decrypt traffic, but it seems that user's credentials are not added to the NTLM header, so they are not passed to ADFS. Does anybody know please, how the correct setup should looks like for ADFS with authentication based on UPN and not SamAccountName?