Create the Trusted User
- Last Updated: February 26, 2024
- 3 minute read
- LoadMaster
- LoadMaster LTSF
- Documentation
Follow the steps below to create the trusted user in the Active Directory settings.
- Log in to your Domain Controller.
- Launch Active Directory Users and
Computers and select Advanced Features from the View menu.
- Click View and click Advanced Features.
- Create a new user as shown
below.
- Set the password to never expire.
- Select the Attribute Editor tab.
- Navigate to servicePrincipalName.
- Select servicePrincipalName and click Edit.
- Type http/trusteduser in the Value to add field and click Add.
- Click Apply and OK. The window must close before you open it again (to see the new Delegation tab).
- Open the user properties window
again and the Delegation tab becomes available.
- Select the Delegation tab.
- Select Trust this user for delegation to specified services only.
- Select Use
any authentication protocol.
- Add the Real Servers and add http as the service. For SharePoint Apps: You might have to add the namespace published by SharePoint to enable KCD, instead of the actual server FQDNs.
- Click Advanced.
- Find the servers by name.
- Select the Expanded check box.
- You can see all servers with
both the host name and the FQDN.Note: If you have a SharePoint environment that uses distributed name spaces, you must register these name spaces instead of the actual servers hosting the content.
- For SharePoint, the settings may need to be configured as outlined in the above screenshot.
Note: The trusted user account must be a member of
the Windows Authorization Access Group. This is required to
properly determine a user’s group membership and therefore effective permissions
over a resource. If a trusted user account is not a member of the Windows Authorization Access Group, the KCD authentication protocol will
not confirm the identity of the trusted users who are attempting to access resources
on a network.