Add Kerberos constrained delegation in Microsoft Active Directory for Microsoft SharePoint
Do not complete this task if you want to configure Kerberos constrained delegation (KCD) for File Share repositories only
- Open Microsoft Active Directory Users and Computers.
- In your domain, click Users.
- Right-click the service account that you want to use to administer Kerberos constrained delegation. Click Properties.
-
In the Microsoft Active Directory account properties, on the Delegation tab, select the following options:
- Trust this user for delegation to specified services only
- Use any authentication protocol
- Click Add.
- Click Users or Computers.
-
In the Enter the object names to select field, type one of the following:
- If the SharePoint web application is running under a domain user account, type the SharePoint Application Pool identity username.
- If SharePoint web application is running under the Network Service account, type the Microsoft SharePoint server name.
- Click OK.
- In the Add Services dialog box, select the HTTP service that corresponds to the SharePoint web applications running under the account specified in step 7.
- Click OK.
- Repeat Steps 4–9 for each application pool identity user and each Web Application identified.