Add Kerberos constrained delegation for file shares
- Open Microsoft Active Directory Users and Computers.
- In your domain, click Computers.
- Right-click the BEMS computer entry. Click Properties.
- Click the Delegation tab.
-
In the Microsoft Active Directory account properties, on the Delegation tab, select the following options:
- Trust this user for delegation to specified services only
- Use any authentication protocol
- Click Add, select Users or Computers, type in the name of the server whose file share needs access and click OK.
- In the list of services, click cifs. Click OK.
- Repeat Step 3 to 6 for each server that has file shares needing access.
- Restart the BEMS instance. Since Kerberos tokens are cached, restarting the BEMS instance ensures that all delegation changes are received on the machines.
- BEMS instance. Since Kerberos tokens are cached, restarting the BEMS instance ensures that all delegation changes are received on the machines.
- Turn on Kerberos constrained delegation.