Health check › Sign-in
Windows sign-in (Kerberos)
Check id signin.windows
What it checks
Checks that the HTTP/ service name for Gate's address is on Gate's account, so browsers on domain PCs can sign people in with their Windows logon.
What you might see
| Info | Windows sign-in is off: people sign in with email and an authenticator. | A choice, not a problem. |
| Problem | Browsers will ask for a ticket to HTTP/gate.corp.example, but Gate's service names only cover http/gate. | The SPN for the name people browse to is missing or on another account. |
| OK | Kerberos sign-in ready for https://gate.corp.example. | Then test from a real browser. |
How to fix it
- In Active Directory Users and Computers, View → Advanced Features, open Gate's account → Attribute Editor → servicePrincipalName, add
HTTP/gate.corp.example. - In Gate: Identity → Active Directory → Save so Gate re-reads its names.
- Browsers also need the sign-in policy: Identity → Browser setup (the Windows installer creates the "Acutis Gate sign-in" Group Policy for you).
- On a domain PC: Identity → Test this browser.
Command line
setspn -Q HTTP/gate.corp.example # who holds it now (must be one account) setspn -S HTTP/gate.corp.example CORP\acutisgate$ klist get HTTP/gate.corp.example # on a domain PC
Full walk-through: Windows sign-in (Kerberos, NTLM) for AI tools.
Related checks
NTLM (older PCs and apps)Gate's service account
Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides
Acutis