Add Kerberos constrained delegation in Microsoft Active
Directory for Microsoft
SharePoint
Microsoft Active
Directory
for Microsoft
SharePoint
There is a limit of 1300 services that can be delegated to one account.
If you want to configure Kerberos constrained delegation (KCD) for File Share repositories only, do not complete this task.
- OpenMicrosoft Active Directory Users and Computers.
- In your domain, clickUsers.
- Right-click theBEMSservice account. For example, BEMSAdmin. ClickProperties.
- In theMicrosoft Active Directoryaccount properties, on theDelegationtab, select the following options:
- Trust this user for delegation to specified services only
- Use any authentication protocol
- ClickAdd.
- ClickUsers or Computers.
- In theEnter the object names to selectfield, type one of the following:
- If theSharePointweb application is running under a domain user account, type theSharePointApplication Pool identity username.
- IfSharePointweb application is running under the Network Service account, type theMicrosoft SharePointserver name.
- ClickOK.
- In theAdd Servicesdialog box, select the HTTP service that corresponds to theSharePointweb applications running under the account specified in step 7.
- ClickOK.
- Repeat Steps 4–9 for each application pool identity user and each Web Application identified.