diff --git a/auth/ldap/ntlmsso_attempt.php b/auth/ldap/ntlmsso_attempt.php
new file mode 100644
index 00000000000..1c05eb73b11
--- /dev/null
+++ b/auth/ldap/ntlmsso_attempt.php
@@ -0,0 +1,34 @@
+config->ntlmsso_enabled)) {
+ print_error('ntlmsso_isdisabled','auth');
+}
+
+$sesskey = sesskey();
+
+//print_header("$site->fullname: $loginsite", $site->fullname, $loginsite, $focus, '', true);
+$msg = '
Attempting SSO...
'
+ . '
';
+redirect($CFG->wwwroot . '/auth/ldap/ntlmsso_finish.php', $msg, 3);
+
+
+
+?>
\ No newline at end of file
diff --git a/auth/ldap/ntlmsso_finish.php b/auth/ldap/ntlmsso_finish.php
new file mode 100644
index 00000000000..e029c350e1f
--- /dev/null
+++ b/auth/ldap/ntlmsso_finish.php
@@ -0,0 +1,30 @@
+config->ntlmsso_enabled)) {
+ print_error('ntlmsso_isdisabled','auth');
+}
+
+// If ntlmsso_finish() succeeds, then the code never returns,
+// so we only worry about failure.
+if (!$authplugin->ntlmsso_finish()) {
+ // Redirect to login, saying "don't try again!"
+ redirect($CFG->wwwroot . '/login/index.php?authldap_skipntlmsso=1',
+ "Single Sign On failed, proceed to normal login", 3);
+}
+?>
\ No newline at end of file
diff --git a/auth/ldap/ntlmsso_magic.php b/auth/ldap/ntlmsso_magic.php
new file mode 100644
index 00000000000..624b6d8ce62
--- /dev/null
+++ b/auth/ldap/ntlmsso_magic.php
@@ -0,0 +1,38 @@
+config->ntlmsso_enabled)) {
+ print_error('ntlmsso_isdisabled','auth');
+}
+
+$sesskey = required_param('sesskey', PARAM_RAW);
+if ($authplugin->ntlmsso_magic($sesskey)) {
+ // Serve GIF
+ $file = $CFG->dirroot . '/pix/spacer.gif';
+
+ // Type
+ header('Content-Type: image/gif');
+ header('Content-Length: '.filesize($file));
+
+ // Output file
+ $handle=fopen($file,'r');
+ fpassthru($handle);
+ fclose($handle);
+ exit;
+} else {
+ print_error('ntlmsso_iwamagicnotenabled','auth');
+}
+
+?>
\ No newline at end of file