Configure resource based Kerberos constrained delegation
- Verify that each domain in your environment has one or more Domain Controllers on a computer that is running an operating system that supports BEMS. For more information, see the BEMS compatibility Matrix.
- Verify that the account that is used to administer Kerberos is a member of the local Administrators group and has the Act as part of the Operating System privilege.
- If you configure resource-based KCD for Microsoft SharePoint, verify that the Microsoft SharePoint server uses Integrated Windows Authentication – Negotiate (Kerberos) for the authentication provider.
- Identify the file share servers and Microsoft SharePoint servers that the Docs service requires access to.
- To verify the delegation is configured correctly, on the Domain controller or another computer in your environment, run Windows PowerShell as an administrator and run one of the following commands:
- If the delegation was set on the server name, type Get-ADComputer <server_name> -Properties PrincipalsAllowedToDelegateToAccount.
- If the delegation was set on the username, type Get-ADUser <user_name> -Properties PrincipalsAllowedToDelegateToAccount.
- To remove the delegation, on the Domain controller or another computer in your environment, run Windows PowerShell as an administrator and run one of the following commands:
- To remove the delegation from a server, type Set-ADComputer <server_name> -PrincipalsAllowedToDelegateToAccount $null.
If you have multiple file share or Microsoft SharePoint servers in your environment, complete this step for each server.
- To remove the delegation from a user, type Set-ADUser <user_name> -PrincipalsAllowedToDelegateToAccount $null.
If you use different usernames for the Microsoft SharePoint and file share servers, complete this step for each username.
- To remove the delegation from a server, type Set-ADComputer <server_name> -PrincipalsAllowedToDelegateToAccount $null.