Hi Paul, more precisions are necessary : - OS : Windows Server 2012 - SAS Version : SAS9.4M3 - SSO Mechanism : IWA Now, I succeeded today an operational single sign-on configuration. Concerning the documentation, here is my feedback: Step 1 : Configure configuration in Active Directory and produce keyab file : Kerberos Delegation with SAS9.4 written by Stuart Rogers Step 2 : SAS Web App Server configuration Support for Integrated Windows Authentication Configuring Web Authentication Starting with the Second Maintenance Release for SAS 9.4 Step 3 : SAS Metadata Configuration How to Configure Web Authentication (optional) : Fallback processing (In my organization, Firefoox can't use IWA, so I need to redirect Firefox's users to a prompt credentials screen) Tips and Best Practices for Configuring Integrated Windows Authentication written by Mike Roda Obviously, all these steps are perfectly described in your post Paul : SAS Mid-Tier (Linux) IWA with Fallback A recommended step in your post, which I have not yet had time to realize, is to redeploy the Web applications to keep the modifications to the passage of the next maintenance (M4 in my case) In conclusion, my configuration was made quite simply. My main recommendation is to validate the compliance of the Kerberos keytab file with the "kinit" executable before proceeding SAS configuration. Gaétan
... View more