Windows Authentication
Specify this authentication when using the Windows domain controller to authenticate users who have
their accounts on the directory server. Users cannot be authenticated if their accounts are not registered
in the directory server. Under Windows authentication, you can specify the access limit for each group
registered to the directory server. The Address Book stored in the directory server can be registered to
the printer, so that user authentication can be enabled without using the printer to register individual
settings in the Address Book.
The first time you access the printer, you can use the functions available to your group. If you are not
registered to a group, you can use the functions available under "*Default Group". To limit the functions
that are available to users, first configure the Address Book.
Windows authentication can be performed using one of two authentication methods: NTLM or Kerberos
authentication. The operational requirements for both methods are listed below:
Operational requirements for NTLM authentication
To specify NTLM authentication, the following requirements must be met:
•
This printer supports NTLMv1 authentication and NTLMv2 authentication.
• A domain controller has been set up in a designated domain.
• NTLM authentication is supported in the following operating systems:
• Windows Server 2003/2003 R2
• Windows Server 2008/2008 R2
• Windows Server 2012/2012 R2
• When running Active Directory, use LDAP to obtain user information. It is recommended to use
SSL to encrypt communication between the printer and the LDAP server. Encryption by SSL is
possible only if the LDAP server supports TLSv1 or SSLv3.
Operational requirements for Kerberos authentication
To specify Kerberos authentication, the following requirements must be met:
• A domain controller must be set up in a designated domain.
• Kerberos authentication is available in the following operating systems which support KDC
(Key Distribution Center):
• Windows Server 2003/2003 R2
• Windows Server 2008 (Service Pack 2 or later)/2008 R2
• Windows Server 2012/2012 R2
• When running Active Directory, use LDAP to obtain user information. It is recommended to use
SSL to encrypt communication between the printer and the LDAP server. Encryption by SSL is
possible only if the LDAP server supports TLSv1 or SSLv3.
2. Configuring User Authentication
40