Add a Desktop SSO Auth Module

An Desktop SSO Auth Module can be used to add a secondary authentication relationship between Access Gateway and a Kerberos instance.

To get started add an Auth Module as described in Add an Auth Module selecting Desktop SSO.

After selecting Desktop SSO the Add New Auth Module page will be displayed, configured for Kerberos.



An active Kerberos Configuration is required before a Desktop SSO module can be created. See Add a Kerberos App for information on adding Kerberos services.

  1. Enter the following details:
    NameName used to identify the Auth Module.Desktop SSO AM

    Secure LDAP

    When checked use LDAPS rather then LDAP

    Defaults to unset

    HostURL to LDAP Server and


    Port for use with Active Directory


    Bind User

    Username used to perform reads and writes.


    Bind User Password

    Bind User Password.



    The base DN from which to perform the search.


    User Search Attribute

    The filter used to match records returned from the Search DN.


    Attributes DN

    Set of attributes returned from Active Directory and sent as SAML attributes to application

    cn, mail, name, userPrincipalName


    Optional description

    Desktop SSO Auth Module

  2. Click the Not Validated ()button when complete.
    Okta Access Gateway will validate the connection.
    On success the button will turn green () and show that the connection is valid.
  3. Once complete click Okay to complete the creation of the Auth Module or Cancel to cancel.