> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v1.0/advanced-help/app_pages/authentication-page.md).

# Authentication Provider

The Access Manager web service allows you to choose one of several different types of authentication providers. It is recommended to use modern authentication using a mechanism such as OpenID Connect, where an identity provider can provider high assurance authentication utilizing passwordless or multi-factor authentication.

Access Manager supports modern identity providers such as Azure AD and Okta out of the box.

## OpenID Connect

OpenID Connect is the preferred authentication provider. Coupled with a modern IDP like Azure AD or Okta, you can provide strong authentication to your application, backed up by multi-factor authentication. See the guides for setting up Access Manager to work with[ Azure AD](/ams/v1.0/configuration/setting_up_authentication/setting-up-authentication-with-azure-ad.md) or [Okta.](/ams/v1.0/configuration/setting_up_authentication/setting-up-authentication-with-okta.md)

Using OpenID Connect requires that your identity provider pass a `upn` claim containing the on-premises Active Directory UPN of your users.

![](https://1984618955-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAsBzwJDeLC2ny10RHLdI%2Fuploads%2Fgit-blob-d2da2fc34783e95fe174e820572ad37c8fdf539b%2Fui-page-authentication-oidc.png?alt=media)

## WS-Federation

WS-Federation can be used to delegate the authentication process to an on-prem ADFS or similar product. Read the[ setup guide](/ams/v1.0/configuration/setting_up_authentication/setting-up-authentication-with-adfs.md) for configuring Access Manager to work with ADFS.

Using WS-Federation requires that your identity provider pass a `upn` claim containing the on-premises Active Directory UPN of your users.

## Smart-card or other certificate

Certificate-based authentication is provided by Access Manager, with the optional support for requiring smart-card authentication.

Certificates must contain a `principal name` attribute in their `Subject Alternative Names` which specifies the user's UPN as found in Active Directory.

Limited support is available for use of [altSecurityIdentities ](/ams/v1.0/configuration/setting_up_authentication/enabling-altsecurityidentities.md)in cases where certificates are used without a UPN, however these are not supported outside the forest where AMS is located.

![](https://1984618955-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAsBzwJDeLC2ny10RHLdI%2Fuploads%2Fgit-blob-df71f06ca966b7869d89cfe909e12a359f45ce56%2Fui-page-authentication-smartcard.png?alt=media)

### Additional mandatory EKUs

Specify any custom EKUs that must be present in the certificate for the authentication to be successful.

### Certificate issuer validation

You must select how you want to validate the certificate issuer. Note that no matter which validation option is selected, at a minimum all certificates must be validated up to a trusted CA on the machine that runs AMS.

#### Trust any certificate issuer trusted by this machine

Use this option to only require that the certificate was issued by an issuer trusted by this machine. This option isn't recommended, as any CA could potentially issue a certificate that you may trust.

#### Trust only Enterprise CAs registered in this domains `NTAuth` store

Active Directory Enterprise CAs are automatically registered in the directory itself as trusted issuers. CAs in the Enterprise `NTAuth` store are trusted to issue logon certificates within the domain. If you select this option, then only certificates issued by one of these CAs are trusted. (Recommended options for smart card certificates)

#### Trust only these specific issuers

This option allows you to import a specific certificate authority's certificate that must be present in the certificate chain for it to be accepted. This can be a subordinate CA, rather than a root certificate. You can add multiple trusted issuers to this list, but only one of them needs to be present in the client's certificate chain.

## Integrated Windows Authentication

The Integrated Windows Authentication (IWA) provider allows users to login with NTLM or Kerberos authentication. In order to use kerberos, the web site host name must be registered on the SPN of the computer object (not the service account). Eg if using a hostname of `accessmanager.lithnet.io`, you'll need to register the SPN `http/accessmanager.lithnet.io` or `host/accessmanager.lithnet.io`. If the host name matches the AD computer name, then no additional SPNs are required.

![](https://1984618955-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAsBzwJDeLC2ny10RHLdI%2Fuploads%2Fgit-blob-1ea128638c4a2ad6fc0b2396c6c6b45381473981%2Fui-page-authentication-iwa.png?alt=media)

### Authentication Scheme

Select one of the following authentication options

* Basic: Uses basic authentication (username/password) - Not recommended
* NTLM: Use NTLM authentication only
* Negotiate: Use kerberos if possible, otherwise fall back to NTLM

## Sign-in restrictions

Specify the users and groups that should be allowed to log into this service, or leave the field blank to allow anyone who successfully authenticates to login


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v1.0/advanced-help/app_pages/authentication-page.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
