<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

Solution Highlight: Hypergate Authenticator for Kerberos SSO on Mobile

Reviewed and updated in October 2026.

Security is a delicate combination of technology and processes, and it ultimately relies on end users acting in line with the defined standards and practices. Authenticating those users is the first step.

What is Hypergate Authenticator? Hypergate Authenticator is a managed app for Android Enterprise and iOS that gives mobile devices Kerberos single sign-on against an existing Active Directory. It talks directly to the domain controllers, so no new servers or middleware are needed, and users reach intranet sites and internal apps without typing their password again.

Why passwords break down on mobile devices

In the past, authentication was relatively easy to manage: users connected to the company network mostly from the same computer, and occasionally from a laptop at an external location.

In the modern workplace, mobile devices are everywhere, whether they are personally owned (BYOD) or corporate-owned and personally enabled (COPE). Users connect to company resources from several devices and many apps, and keeping passwords in sync across all of them is a challenge.

Security rules have also made the once simple password overly complex: combinations of letters, numbers and symbols that are hard to remember, and in many organizations a forced change every few months. That pushes people toward weak, easy-to-guess passwords or the same password for every account, which puts security at risk. Current guidance agrees: NIST's SP 800-63B says verifiers shall not require users to change passwords periodically, but shall force a change when there is evidence that a password has been compromised.

This is where we recommend single sign-on (SSO), which helps users overcome the password problem without weakening security. For mobile devices in an Active Directory environment, Hypergate Authenticator is a strong candidate. If you want the background on simpler security first, read Security Through Simplicity, the article this one originally followed.

How Hypergate Authenticator works

Hypergate Authenticator brings native Kerberos authentication to Android devices and also supports iOS. It requests tickets directly from the Kerberos Key Distribution Center on your domain controllers, the same way domain-joined Windows clients do. That has several practical consequences:

  • No new servers, proxies or middleware, and no changes to your existing Active Directory
  • Support for complex setups, including multiple forests and air-gapped networks without internet access
  • Users can change an expired password directly on the device, without needing a Windows computer
  • Browsers such as Google Chrome and Microsoft Edge authenticate to Kerberos-protected intranet sites in the background; in general, apps that support Chrome Custom Tabs work out of the box

Hypergate Files for file shares

The companion app Hypergate Files uses the same Kerberos sign-in to give Android and iOS devices access to on-premises SMB2 and SMB3 shares, including NetApp backends. Files open in their native apps such as Word, Excel or a PDF viewer, without a special viewer.

Why Kerberos on mobile matters now

Microsoft has announced that it will disable NTLM by default in future Windows releases. Mobile devices that still reach intranet sites, internal web apps or file shares via NTLM need a Kerberos path. We explain the background and a migration plan in Replacing Acronis Cyber Files and leaving NTLM: Kerberos SSO for Android without the cloud.

Key benefits

  • Easy integration: no changes to your existing Active Directory infrastructure
  • Fast deployment: Hypergate Authenticator is pushed to the device as a managed app, with configuration from your UEM
  • Unobtrusive for users: the app works in the background and authenticates requests to internal Kerberos-protected services
  • Broad UEM compatibility: Microsoft Intune, Ivanti, Omnissa Workspace ONE UEM (formerly VMware), BlackBerry UEM, SOTI and 42Gears
  • Works with standard apps: Google Chrome, Microsoft Edge and other apps that support Chrome Custom Tabs; ISEC7 MAIL supports Hypergate as a sign-in method
  • Lower support costs: fewer password-related help desk calls, because users manage their own credentials on the device

Who does what

Hypergate, a Swiss vendor (Papers AG), makes the apps. ISEC7 is a Hypergate partner for Germany, the United Kingdom and the United States and takes care of integration and rollout, and of operation if you want it. SSO is one part of a broader access strategy; see also Demystifying Security: Multi-Factor Authentication and Demystifying Security: Zero Trust.

Frequently asked questions

Does Hypergate need additional servers?

No. Hypergate Authenticator connects directly to your existing domain controllers using Kerberos. There is no gateway, proxy or cloud service in between, which is why it also works in air-gapped networks.

Which devices and UEM platforms are supported?

Android Enterprise devices from Android 7.0 onward, and iOS. The app is distributed and configured through your UEM; Microsoft Intune, Ivanti, Omnissa Workspace ONE UEM, BlackBerry UEM, SOTI and 42Gears are supported.

How does Hypergate help with the move away from NTLM?

The app obtains its Kerberos ticket directly from the domain controller, either with a user certificate delivered through the UEM or with username and password. No NTLM hashes are created that could be captured and reused, and the mobile sign-in appears in the domain controller log as a Kerberos ticket request.

Can users change their Active Directory password on the phone?

Yes. When a password expires, users change it directly on the device, without having to go to a Windows computer.

Planning SSO for your mobile fleet or a move away from NTLM? Our page on Acronis Cyber Files and NTLM summarizes the options, our team supports endpoint management projects end to end, and our Android trainings prepare your administrators. Contact us with any questions.