Start a conversation

Configuring Automatic User Authentication Using NTLM


Kerio Control supports automatic user authentication by the NTLM method (NT LAN Manager authentication from web browsers). Once authenticated for the domain, users do not need to enter their usernames and passwords.

This article shares the specific conditions and configuration settings for the correct functioning of the NTLM by covering the following topics:



Please ensure meeting the following requirements:

Back to top


Configuring NTLM in Kerio Control

  1. In the administration interface, go to Configuration > Domains and User Login.
  2. Go to the Authentication Options tab.
  3. (Optional) Check the option Always require users to be authenticated when accessing web pages.
  4. Check Enable automatic authentication using NTLM.


  5. Click Apply.

Note: Rejoin the domain and restart the Kerio Control installation to clear the NTLM cache for troubleshooting purposes.

Once Kerio Control is configured correctly to use the NTLM authentication, configure the web browsers on client hosts using the steps indicated in the following sections. For proper functioning of NTLM, only use the following web browsers:

  • Microsoft Internet Explorer
  • Mozilla Firefox
  • Google Chrome

Note: Microsoft Edge does not support NTLM yet.

Back to top


Configuring Microsoft Internet Explorer Settings

In Internet Explorer, you must enable integrated Windows authentication, and add the Kerio Control server name to trusted servers by following these steps:

  1. Open Internet Explorer.
  2. Click Tools > Internet Options.
  3. Click the Advanced tab.
  4. Check Enable integrated Windows Authentication.


  5. Restart Internet Explorer.

Internet Explorer should now be correctly configured, and NTLM authentication should work. This means that the users do not have to authenticate with Kerio Control credentials.

If NTLM does not work, you may have problems with Kerio Control server name. In this case, follow these steps: 

  1. Go to Tools > Internet Options.
  2. Click the Security tab.
  3. Click Local Intranet.
  4. Click Sites.


  5. In the Local Intranet dialog box, click Advanced.
  6. Add the Kerio Control server name to the list of trusted servers. For increased security, enter the server name in this format:

Back to top


Configuring Mozilla Firefox Settings

  1. Open Mozilla Firefox.
  2. Enter about:config in the address bar.
  3. Use the filter to search for network.automatic-ntlm-auth.trusted-uris.
  4. Double-click the item.
  5. In the dialog box, add the Kerio Control server name. For increased security, enter the server name in this format:

Mozilla Firefox should now be correctly configured, and NTLM authentication should work. This means that the users do not need to authenticate with Kerio Control credentials.

Back to top


Configuring Google Chrome Settings

Chrome uses Internet Explorer's Security Configuration, so one way to configure Chrome's settings is to configure Internet Explorer. Google Chrome adopts the same settings so that NTLM authentication will work.

Back to top

Choose files or drag and drop files
Was this article helpful?
  1. Priyanka Bhotika

  2. Posted
  3. Updated
