Health check › Sign-in
NTLM (older PCs and apps)
Check id signin.ntlm
What it checks
Only when NTLM is turned on: checks that a domain controller can verify NTLM answers for Gate, and that relay protection can read the certificate browsers see.
What you might see
| Info | NTLM is off: only Kerberos sign-in. | PCs that open Gate by IP address, or old apps, will be refused. |
| Problem | NTLM is on but this server's secure channel to the domain is not working. | Windows edition: the server's trust with the domain is broken. |
| Problem | NTLM is on but Gate's domain trust is not working (winbind not running). | Linux appliance: Gate's computer-account join needs renewing. |
| Check | NTLM on with relay protection OFF. | Works, but less safe. |
How to fix it
Windows Server:
Command line (as an administrator)
nltest /sc_verify:CORP Test-ComputerSecureChannel -Repair -Credential CORP\admin
Linux appliance:
- Identity → Active Directory, enter the service account password, Save: Gate re-joins as its computer account.
- If relay protection cannot read the certificate, check
GATE_TLS_CERT_FILEpoints at the certificate your HTTPS proxy serves (the installer sets this).
- To turn relay protection back on: Identity → Active Directory, NTLM options. Each NTLM sign-in is marked in the audit trail, so you can see who still needs it.
Related checks
Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides
Acutis