Matthew McDermott, MVP

General ramblings from a SharePoint MVP about SharePoint and Microsoft technologies related to collaboration, web content management and productivity.

SSO Configuration Weirdness

There is a LOT of great information on how to configure SSO for SharePoint. If you are still jaded because of the limited capability of SSO in 2003, you have to take a fresh look at SSO in 2007. As far as I can tell the service has not changed substantially (if at all). The biggest change is that SharePoint Designer now understands SSO and you can use it for your Data Form Web Parts and the BDC.

With that in mind I was configuring SSO and kept running into the error message:

Login failed for user 'NT AUTHORITY\ANONYMOUS LOGON'

What?

I double check everything under my control. This was a medium farm environment, so there are a bunch of places to check, but everything was right. On a hunch I asked about the group that IT provisioned for me. Turns out the SSO Admins Group that was provisioned for me was not a Global Group (it was set as Universal). Changing the group to Global made everything work.

Anyway, here are some great resources in your quest:

TechNet: Configure Single Sign-on

Brett Lonsdale's Blog: SSO is So Easy

Dave Wollerman's SharePoint Blog: SharePoint 2007 Single Sign-On Setup

Posted by Matthew McDermott on Friday, 30 May 2008 04:28
1 Comment | Filed under: SharePoint 2007
Bookmark this post with:        

Comments

On 30 May 2008 01:14, whall said:

This information is SSO enthralling... (sarcasm mode now turned off) SSOeriously, tho, we are excited to actually try it in our environment once our migration is complete. Although we try as good IT/IS people to have centralized sign-on sources that various apps can query, we still have silos of information that have separate authentication schemes.

Leave a comment

Name (required)

Url

Email

Comments

Complete this section to post your comment