Add Kerberos constrained delegation for file shares

The main difference between sharing files in File Share repositories, compared to sharing apps (for example, Microsoft SharePoint), is that the delegation is to the computer hosting the BEMS instance account and not to the Docs service process user, BEMSAdmin.
  1. Open Microsoft Active Directory Users and Computers.
  2. In your domain, click Computers.
  3. Right-click the BEMS computer entry. Click Properties.
  4. Click the Delegation tab.
  5. In the Microsoft Active Directory account properties, on the Delegation tab, select the following options:
    • Trust this user for delegation to specified services only
    • Use any authentication protocol
  6. Click Add, select Users or Computers, type in the name of the server whose file share needs access and click OK.
  7. In the list of services, click cifs. Click OK.
  8. Repeat Step 3 to 6 for each server that has file shares needing access.
  9. Restart the BEMS instance. Since Kerberos tokens are cached, restarting the BEMS instance ensures that all delegation changes are received on the machines.
Restart the