Android Enterprise Single Sign-On (SSO) and Kerberos

Hello,
I would like to share a great news about Android Enterprise: many customers are requesting SSO as soon as we integrate Android Enterprise apps. As of August 2018 there is no native Kerberos integration in Android, as opposed to iOS. Google told us during the Android Enterprise Summit that they still have some “open” challenges with Kerberos on Android.

We have now such a product called Hypergate, which is generic, works with all EMMs and provide a secure SSO with Kerberos on Android Enterprise. As an example, you may use Chrome to access your internal apps/websites without any login.
This requires a per-App VPN solution like MobileIron Tunnel, or that the device has connectivity (TCP,UDP) in the internal network.

The solution is compatible with Basic authentication (towards the KDC) and also Certificate-based Authentication.

Have a look at https://hypergate.me/ and Nomasis Managed Mobility - mobile Services umgesetzt mit dem MOC

We would be happy to give you more information if requested.

Best regards,
Alexandre Chappuis

1 Like

I’ve heard there is a solution coming from Google also in testing, though haven’t seen it first-hand. When I know more/can share I will do :wink:

Jason, do you have any news on this topic?

It seems like a pretty low-priority project for them, and I haven’t seen any movement. Hypergate looks like they way to go generally considering everything I’ve seen/heard since last year :+1:

There is now a new URL for the Hypergate’s website: https://hypergate.com - and plenty of new partners worldwide!

Hey guys, ¨
Thanks for your post. Hypergate is still the solution to go here. Around 100K User around the world are using it.
If you need help in setting it up or looking for a trial contact us through our website www.hypergate.com

1 Like

The most secure way to go, is with certificate authentication. Hypergate supports certificate authentication with Kerberos and Active Directory. With the Hypergate Office 365 Connector certificated based authentication is even supported with all Microsoft products. Even if you suse Microsoft Authenticator you will need a onetime password in the setup process, with Hypergate 365 Connector we dont need one time password, we work with the Trusted Execution Environment on the devices.

1 Like

hey Jason, Do you think this Hypergate Solution ist still the way to go?