Configuring Windows for Kerberos Delegation

Before applying Kerberos Delegation to a Network Share Folder workflow, Administrators must use Windows Administrative Tools > Active Directory Users and Computers to configure Kerberos Delegation.

The Administrator must complete the following tasks.

See Access Windows Administrative Tools > Active Directory Users and Computers for more information.

To configure Kerberos Delegation

For the Service Account user

A service account is a special user account that an application or service uses to interact with an operating system.

  1. Select Users on the Active Directory Users and Computers pane.

  2. Create or right-click the Service Account User and select Properties.

  3. Select the Delegation tab.

  4. Select the following options:

    • Trust this user for delegation to specified services only

    • Use any authentication protocol.

  1. Select the services you want to use; for example, cifs, clipsrv, and more, if necessary.

  1. Click Apply and OK.

For the computer

  1. Select Computers on the Active Directory Users and Computers pane.

  2. Find and right-click the appropriate computer(s) and select Properties.

  3. Select the Delegation tab.

  4. Select the following options:

    • Trust this computer for delegation to specified services only

    • Use any authentication protocol

  1. Select the services you want to use; for example, cifs, clipsrv, and more, if necessary.

  1. Click Apply and OK.

For the Local Security Policy computer/account

  1. On the Start menu, select Windows Administrative Tools or type Administrative Tools in the Taskbar Search box.

  2. Select Local Security Policy.

  3. Select Local Policies.

  4. Select User Rights Assignments.

  5. Select Act as part of the operating system.

  6. Select Add User or Group.

  7. Type the name of the Service Account User in the Enter the object names to select box.

  8. Click OK.

Note: This is required. Restart the computer(s) with Kerberos Delegation after configuration is complete.

See also

About Kerberos Delegation

Applying Kerberos Delegation to a Network Share Folder Workflow

Kerberos Delegation in Action