Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Tech News
  • Contact
  • Toggle search form

How to configure a service account for Kerberos delegation

Posted on 17/03/202122/08/2026 IT Expert By IT Expert 1 Comment on How to configure a service account for Kerberos delegation
  1. Home
  2. Windows Server
  3. How to configure a service account for Kerberos delegation
Kerberos authentication

Kerberos is a network authentication protocol. It is designed to provide strong authentication for client/server applications by using secret-key cryptography. Kerberos delegation is to enable an application to access resources hosted on a different server t. For some related content on Active Directory, see the following guides. The sign-in method you are trying to use is not allowed, Active Directory Authentication methods: Kerberos and NTLM, and the concept of AD Computer Account.

You may have so many reasons to configure delegation for Kerberos authentication. For me, I had wanted to test MBAM 2.0 but later decided to install MBAm 2.5 with SP1 and therefore had no need to configure Kerberos delegation.

Regardless, I decided to describe the steps here for your need 🙂 The following are the types of delegation. (1) Unconstrained delegation (2) Constrained delegation and (3) RBCD (Resource Based Constrained Delegation. Kindly take a look at this guide “” for more information.

You may also want to visit the following interesting articles. What are the merits and demerits of Local System Account and Service Logon Account, how to delete and restore objects using Active Directory Administrative Center, and what are the differences between an Active Directory contact and a user account object?

Configure a service account for Kerberos delegation

Furthermore, If you wish to configure constrained delegation when you are using MBAM 2.5 only, please see this link.

Navigate to Active Directory Users and Computers, click on the right container housing the account (service account), and moreover, Find the app pool credentials (in my case a service account named MBAM-IISAP-SVC), right-click, and go to properties.

Service account setup

In addition, Click the delegation, and click on the option to trust the user for delegation to any (Kerberos only) and click on OK.

Note: If you do want to trust this user to any services, Please select "Trust this user for delegation to the specified services only" and add the service.

Security permissions for service accounts

That is all that you need to do to configure Kerberos delegation for a user account (service account).

Alternatively, you could use Active Directory Administrative Center. Here you will have to launch the Active Directory Administrative Center as shown below

Service account setup

Locate the container (OU) that the service account or user account is located in and right click on the user. Alternatively, you could click on Properties to display the user account properties”.

Screenshot-2021-03-17-at-19.32.23

Click the delegation, and click on the option to trust the user for delegation to any (Kerberos only) and click on OK.

Note: If you do want to trust this user to any services, Please select "Trust this user for delegation to the specified services only" and Add the service.

Screenshot-2021-03-17-at-19.47.55

I hope you found this blog post helpful. If you have any questions, please let me know in the comment session.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Active Directory, Active Directory Administrative Center, Active Directory Domain Services, Kerberos, Windows 10

Post navigation

Previous Post: Unable to install Microsoft Bitlocker Administration: Uninstall your current version of MBAM and run setup again
Next Post: How to deploy MBAM for BitLocker Administration

Related Posts

  • windows pe screenshot1 rcm1200x0
    Workaround and Permanent fix for this snap-in performed a non-valid operation and has been unloaded: To continue using this snap-in restart MMC or try loading the snap-in again Windows Server
  • screenshot 2020 04 09 at 02.57.27
    Import certificates into Trusted Root and Personal certificate store Windows Server
  • fix Client Certificate Mapping Authentication error
    How to fix Client Certificate Mapping Authentication error Backup
  • How to upgrade domain controllers e1775563888303
    Build a New DC vs Swing Migration: Upgrade Server OS Correctly Windows Server
  • MBAM Replacement
    MBAM extended support ends April 2026: Find alternative solution Security | Vulnerability Scans and Assessment
  • Slide1
    Configure Desktop Wallpaper and Screen Saver Management via GPO Windows

More Related Articles

windows pe screenshot1 rcm1200x0 Workaround and Permanent fix for this snap-in performed a non-valid operation and has been unloaded: To continue using this snap-in restart MMC or try loading the snap-in again Windows Server
screenshot 2020 04 09 at 02.57.27 Import certificates into Trusted Root and Personal certificate store Windows Server
fix Client Certificate Mapping Authentication error How to fix Client Certificate Mapping Authentication error Backup
How to upgrade domain controllers e1775563888303 Build a New DC vs Swing Migration: Upgrade Server OS Correctly Windows Server
MBAM Replacement MBAM extended support ends April 2026: Find alternative solution Security | Vulnerability Scans and Assessment
Slide1 Configure Desktop Wallpaper and Screen Saver Management via GPO Windows

Comment (1) on “How to configure a service account for Kerberos delegation”

  1. Avatar photo Long says:
    21/02/2024 at 11:11 AM

    how to set constrained delegation for MBAM?

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • Banner 1
    How to Deploy a React Application on Netlify Automation
  • FileNotFoundError Errno 2 No such file or directory
    Fix FileNotFoundError: [Errno 2] No such file or directory Scripts
  • WinServer
    Log Off: How to sign out of Windows Server 2012 Windows Server
  • redirects3endpoint
    How to redirect requests for your bucket’s website endpoint to another bucket or domain AWS/Azure/OpenShift
  • featureunions
    How to Install Unison on Linux System Linux
  • wac
    Fix Windows Admin Center cannot be reached Windows
  • rdp
    How to fix Remote Desktop can’t connect to the remote computer for one of these reasons Windows Server
  • Azure upgrade adconnect 1 e1782081079535
    Upgrading Azure AD Connect to Microsoft Entra Connect Sync AWS/Azure/OpenShift

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,762 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.