Add Kerberos constrained delegation in Microsoft Active
Directory for Microsoft
SharePoint
Kerberos
constrained delegation in Microsoft Active
Directory
for Microsoft
SharePoint
There is a limit of 1300 services that can be delegated to one account.
If you want to configure
Kerberos
constrained delegation (KCD) for File Share repositories only, do not complete this task.Verify that you have Created Service Principal Names.
- Open.Microsoft Active Directory Users and Computers
- In your domain, clickUsers.
- Right-click the service account that you want to use to administerKerberosconstrained delegation. ClickProperties.
- In theMicrosoft Active Directoryaccount properties, on theDelegationtab, select the following options:
- Trust this user for delegation to specified services only
- Use any authentication protocol
- ClickAdd.
- ClickUsers or Computers.
- In theEnter the object names to selectfield, type one of the following:
- If theSharePointweb application is running under a domain user account, type theSharePointApplication Pool identity username.
- IfSharePointweb application is running under the Network Service account, type theMicrosoft SharePointserver name.
- ClickOK.
- In theAdd Servicesdialog box, select the HTTP service that corresponds to theSharePointweb applications running under the account specified in step 7.
- ClickOK.
- Repeat Steps 4–9 for each application pool identity user and each Web Application identified.