Security

Previous Topic Next Topic

Trusted for Delegation

To allow delegation of security credentials, you must also set the Computer is trusted for delegation option on each computer that will be used by the Web application.

To set the Computer is trusted for delegation option

  1. On the Tools menu, click Active Directory Users and Computers.
  2. Click the domain name node to expand it.
  3. Click the Computers node to expand it.
  4. Right-click on the computer in question.
  5. Select Properties.
  6. Select Computer is trusted for delegation.

Perform these steps on the Domain Controllers node also.

You can override this option on a per-user account basis. For example, it is considered bad security practice to enable account delegation for the Administrator account, because this account is a highly trusted account.

To override the Computer is trusted for delegation option

  1. On the Tools menu, click Active Directory Manager.
  2. Click the Users node to expand it.
  3. Right-click on the user account in question.
  4. Select Properties.
  5. Click the Account tab.
  6. Deselect Account is sensitive, do not delegate in the Account options.

© 1997-1999 Microsoft Corporation. All rights reserved.