Acutis Gate logo Acutis Gate Health check help

Health check › Sign-in

Windows sign-in (Kerberos)

Check id signin.windows

What it checks

Checks that the HTTP/ service name for Gate's address is on Gate's account, so browsers on domain PCs can sign people in with their Windows logon.

What you might see

InfoWindows sign-in is off: people sign in with email and an authenticator.A choice, not a problem.
ProblemBrowsers will ask for a ticket to HTTP/gate.corp.example, but Gate's service names only cover http/gate.The SPN for the name people browse to is missing or on another account.
OKKerberos sign-in ready for https://gate.corp.example.Then test from a real browser.

How to fix it

  1. In Active Directory Users and Computers, View → Advanced Features, open Gate's account → Attribute Editor → servicePrincipalName, add HTTP/gate.corp.example.
  2. In Gate: Identity → Active Directory → Save so Gate re-reads its names.
  3. Browsers also need the sign-in policy: Identity → Browser setup (the Windows installer creates the "Acutis Gate sign-in" Group Policy for you).
  4. On a domain PC: Identity → Test this browser.

Command line

setspn -Q HTTP/gate.corp.example                 # who holds it now (must be one account)
setspn -S HTTP/gate.corp.example CORP\acutisgate$
klist get HTTP/gate.corp.example                 # on a domain PC

Full walk-through: Windows sign-in (Kerberos, NTLM) for AI tools.

Related checks

NTLM (older PCs and apps)Gate's service account

Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides