When you use Active Directory when you set up single sign-on authentication for Workspace ONE UEM managed iOS mobile devices, you set up a trust relationship between Active Directory and Workspace ONE UEM. After that, you enable the Mobile SSO for iOS authentication method in Workspace ONE Access.
After you configured the certificate authority and certificate template for Kerberos certificate distribution in the Active Directory Certificate Services, you enable Workspace ONE UEM to request the certificate used for authentication and add the certificate authority to the Workspace ONE UEM console.
Procedure
What to do next
Configure the Certificate Template in Workspace ONE UEM.