---
title: Kerberos Authentication for Synthetic Monitoring
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Synthetic Testing and Monitoring > Synthetic Monitoring Guides >
  Kerberos Authentication for Synthetic Monitoring
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Kerberos Authentication for Synthetic Monitoring
Available for:
{% icon name="icon-browser" /%}
 Browser Tests | 
{% icon name="icon-api" /%}
 API Tests 
## Overview{% #overview %}

Datadog Synthetic Monitoring enables proactive monitoring of web applications and APIs using Kerberos SSO authentication with Microsoft Active Directory. This allows continuous testing of critical user journeys and HTTP endpoints on your internal Windows sites.

## Prerequisites{% #prerequisites %}

- A Windows private location (managed locations do not support Kerberos authentication).
- A Windows site with Kerberos authentication integrated with Active Directory (usually hosted on IIS).
- A Windows server that is domain-joined to the Active Directory.
- A domain user account with Active Directory authentication access to the Windows site.
- Synthetic Monitoring tests must run on a Windows private location that is configured to authenticate with Active Directory. For more information, see the [Windows private locations](https://docs.datadoghq.com/synthetics/platform/private_locations.md?tab=windows#prerequisites) prerequisites documentation.

## Installation{% #installation %}

1. Create your [Windows private location](https://docs.datadoghq.com/synthetics/platform/private_locations.md?tab=windows#create-your-private-location) on the Windows server joined to the Active Directory domain.
1. Set up the [Synthetic Monitoring private location worker](https://docs.datadoghq.com/synthetics/platform/private_locations.md?tab=windowsviagui#install-your-private-location) to run as a Windows service.
1. Configure the private location service to use your Active Directory domain account credentials:
   - Open `services.msc`, navigate to Datadog Synthetics Worker > Properties > log on > this account, and enter your domain account credentials.
1. Configure your tests:
   - **Browser Tests**: Record your test from a browser session running directly on a domain-joined Windows host. For example, connect to your Windows private location using Remote Desktop Protocol (RDP) and record from there. Recording from a machine outside the Active Directory domain sends requests over the public internet without any Kerberos credentials attached, causing a login prompt.
   - **API Tests**: Set the Domain field under the Kerberos tab to the full Service Principal Name (SPN) of the target service. For example, `HTTP/targetsite.yourdomain.com`, or `HTTP/targetsite.yourdomain.com:port` if the site is registered with a non-default port.

{% image
   source="https://docs.dd-static.net/images/synthetics/guide/kerberos-authentication/api_test_kerberos.8e5f388b0979e30a62dc30cc1aacb129.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/synthetics/guide/kerberos-authentication/api_test_kerberos.8e5f388b0979e30a62dc30cc1aacb129.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="API Test creation with the Advanced options expanded, highlighting the Authentication tab and Kerberos authentication type" /%}

## Further Reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Monitor your Synthetic private locations with Datadog](https://www.datadoghq.com/blog/synthetic-private-location-monitoring-datadog)
- [Proactively monitor Kerberos-authenticated web apps and APIs with Datadog Synthetics](https://www.datadoghq.com/blog/kerberos-synthetics/)
- [Learn about Passkeys in Browser Tests](https://docs.datadoghq.com/synthetics/guide/browser-tests-passkeys.md)
