Skip to main content

August 11, 2026

Create Custom Lookup Value for iOS Mobile SSO Kerberos Principal Name

If your Active Directory includes multiple employee user names configured with the same FirstName and LastName, you must create a custom attribute in the Devices & Users > General > Lookup Fields page in the Workspace ONE UEM console to use as the Kerberos Principal Name in the iOS SSO profile configured in the Workspace ONE UEM console.

Prerequisites

To learn more about lookup fields in the Workspace ONE UEM console, see Devices & Users / General / Lookup Fields.

Procedure

  1. In the Workspace ONE UEM console, navigate to Groups & Settings > All Settings.

  2. In the Devices & Users section, select General and then click Lookup Fields.

  3. Click ADD CUSTOM FIELD and configure the following.

    OptionDescription
    Standard Lookup FieldIn the drop-down menu, select User Principal Name.
    NameEnter a name for the custom look up field. For example, KerberosSPN
    DescriptionEnter the description of this custom field, for example, Custom Kerberos User Principal Name lookup
    Allow InheritanceSelect Enable.
    Custom typeSelect Regex Lookup.
    Regular ExpressionEnter ^[^@]+.
  4. Click SAVE.

    The custom lookup name is listed in the Lookup table page.

  5. To add the custom lookup name to the iOS profile, in the Workspace ONE UEM console, navigate to the iOS Resources >Profiles page and select the iOS device profile to edit. In the Single Sign-On page Kerberos Principal Name text box, enter the custom lookup name that you created.

  6. Select SAVE & PUBLISH.

    See the Workspace ONE UEM documentation, Configure an iOS Profile > Single Sign-On Profile for iOS.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…