Changes

Jump to navigation Jump to search

Windows Admin Center Kerberos Constrained Delegation

1,016 bytes added, 12:28, 10 October 2019
Created page with "In order to have a "Single Sign On" experience in the Windows Admin Center, you must delegate kerberos from the server that WAC is installed on, down to the endpoint that is b..."
In order to have a "Single Sign On" experience in the Windows Admin Center, you must delegate kerberos from the server that WAC is installed on, down to the endpoint that is being managed. The following commands can help with this.

*Open Powershell as an administrator and enter the following commands to delegate to any windows servers in your active directory.
::<code>$gateway = "<strong>NameofYourGateway</strong>"</code>
*Notice that the bold text should be the name of the host of your windows admin center installation.
::<code>$gatewayObject = Get-ADComputer -Identity $gateway</code>
::<code>Get-ADComputer -Filter { OperatingSystem -Like '*<strong>Windows Server</strong>*' } | Set-ADComputer -PrincipalsAllowedToDelegateToAccount $gatewayObject</code>
*Notice that the Bold text of "Windows Server", this can be changed to reflect any computer object in Active Directory by changing it to reflect some part of the "name" field under the "Operating System" tab in Active Directory.
[[Category:Microsoft]]

Navigation menu