For the complete documentation index, see llms.txt. This page is also available as Markdown.

LDAP / Kerberos Login (SSO)

Directory-based sign-in (LDAP / Active Directory) and optional silent Kerberos SSO for on-premise deployments — and the information we need from you to set it up.

On-premise deployments can authenticate users against your existing directory instead of separate We360 credentials. Two modes are supported:

  • Directory login — users sign in with their existing directory (LDAP / Active Directory) username and password.

  • Silent SSO (Kerberos) — on domain-joined Windows machines, users are logged in automatically from their existing Windows session, with no username/password prompt.

Both are optional and are configured per deployment.

We360 performs the configuration. You do not need to set up anything in the application. We only need some details about your directory environment, listed below. The Kerberos (silent SSO) mode is optional — set it up only if you want zero-prompt login.

Information we need from you

To enable this, we ask your IT / directory administrator for the following. The downloadable form at the bottom of this page has a fill-in table for each item.

  1. Directory server — type (Active Directory / other LDAP), version, host name(s), port, and whether the connection uses LDAPS/TLS (plus the CA certificate if it is issued by a private CA).

  2. Service (bind) account — a dedicated read-only account we use to look up users: its distinguished name (DN) and password.

  3. Directory structure — the base DN and the specific container(s)/OU where the users who should log in are located, and whether all of them or only a subset (e.g. a group) get access.

  4. User attributes — which fields hold the login username, email, and name, and a stable unique identifier.

  5. Kerberos / SSO (optional) — the Kerberos realm, KDC (domain controller) host names, confirmation that machines are domain-joined, and a service account + SPN + keytab your AD administrator generates for the login service.

  6. Network & environment — connectivity from the We360 server to the directory (and KDC), DNS resolution, and clock synchronization.

  7. Test accounts (optional) — one or two non-critical accounts so we can validate login before rollout.

Requirements form

Download, complete the "Your value" column, and return the form to your We360 contact. Items marked (secure) are sent separately via the secure channel.

We360 — Directory Integration (LDAP / Active Directory) Information Request

Last updated

Was this helpful?