Turn on Kerberos constrained delegation
- Only Windows authentication in Microsoft SharePoint is supported. Forms-based and claims-based authentication are not supported.
- IP addresses are not allowed in the Microsoft SharePoint URLs and File Share paths that you configure in BEMS.
- In the BlackBerry Enterprise Mobility Server Dashboard, under BlackBerry Services Configuration, click Docs.
- Click Settings.
- In the Kerberos Constrained Delegation section, select the Enable Kerberos Constrained Delegation check box.
- If your environment requires a separate account to administer KCD, select Use Separate Service Credentials for Kerberos Constrained Delegation check box.
- Enter the credentials for the account that will be used to authenticate to SharePoint for KCD.
- Click Save.
- Restart the Good Technology Common Services service.
-
On the computer that hosts the Docs service, grant the Act as part of the operating system privilege to the BEMS server account (for example, BESAdmin).
- Run the Local Security Policy administrative tool.
- In the left pane, expand Local Policies.
- Click User Rights Agreement.
- Configure the service account for the Act as part of the operating system permission.
- Click OK.