Skip Navigation

Configuring 
Kerberos
 Constrained Delegation

Kerberos
 Constrained Delegation allows users to access enterprise resources without having to enter their network credentials. 
Kerberos
 Constrained Delegation uses service tickets that are encrypted and decrypted by keys that don't contain the user’s credentials.
When 
Kerberos
 Constrained Delegation is configured, the app delegates authentication to 
BlackBerry UEM
 to act on its behalf to request access to an enterprise resource.
Set up 
Kerberos
 Constrained Delegation using the following guidelines:
  • Enable 
    Kerberos
     authentication (under 
    Windows
     authentication) for the 
    Microsoft Exchange Web Services
     web server in 
    Microsoft Internet Information Services
     (IIS).
  • In the "Active Directory Users and Computers" 
    Microsoft
     Management Console (MMC), on the Delegation tab, add the 
    Microsoft Exchange Web Services
     web server’s HTTP service for the 
    Good
     Admin account.
  • If 
    Kerberos
     Constrained Delegation is enabled, users can’t enter their authentication credentials (usernames and passwords). Authentication is delegated to 
    BlackBerry UEM
    .
To enable 
Kerberos
 Constrained Delegation for a 
BlackBerry Dynamics
 app, select the 
Permit the use of Kerberos Constrained Delegation
 setting in the configuration settings for the app. For detailed instructions, see the administration content for the app.