Set the type of desktop software authentication
- In the navigation bar, click
.
- In theUserssection, clickUser Authentication.
- On theUser Authenticationwindow, in theAssign Authentication Methods to Applicationssection, select one of the following authentication methods from theDesktop App>Authentication Methodlist:
- LDAP Attribute: This option enables the desktop app to authenticate with an Active Directory attribute that you provide in theAttributefield. The desktop app queries this attribute directly from the signed-in user's directory profile and sends it to the server. This option allows the desktop app to operate while sending less user information to the server. When this option is selected, the desktop app does not send Windows user names or domain names in sign on or check update query strings.
- This option requires desktop app version 6.2.x.271 or later.
- Smart Card: This option enables smart card authentication. Select the number of client certificates to collect. The recommended value is 3.
- From theNumber of Certificateslist, select the number of client certificates to collect. The recommended value is 3.
- Optionally, in theRegular Expressionfield, enter a regular expression in the following format:UID=(? <edipi>\d{8,10}). ContactBlackBerry AtHoccustomer support to configure this field.
- Optionally, in theClient Regular Expressionfield, enter a client regular expression in the following format:.*?(^)(?:(?!\s-[A||E||S]).)*. This format extracts information from the client certificate subject name to find the identical certificates for authentication. The regular expression provided in the UI is a sample expression that may not be suitable for your environment. You can build you own regular expression or contactBlackBerry AtHoccustomer support to configure this field.
- Username and Password: This option requires users to sign on to the desktop app using theirBlackBerry AtHocusername and password.
- Windows Authentication: This option configures the desktop app to use only the Windows username and password or to use both the Windows username and the domain.
- Optionally, if LDAP Attribute, Smart Card, or Windows Authentication is selected, you can select theCreate new user if an account is not foundcheck box to configure the desktop app to create a user at sign on if the user does not already exist.
- ClickSave.