Blackberry PRD-10459-003 Administration Guide - Page 270

to a shared folder, Con the Microsoft Active Directory account to delegate access to a shared

Page 270 highlights

Administration Guide Configuring Integrated Windows authentication so that users can access resources on your organization's network 6. Select the HTTP service type for the user account or application server that you specified. 7. Repeat steps 1 to 6 for each intranet site that you want to turn on integrated Windows authentication for. After you finish: • If required, configure BlackBerry® MDS Connection Service to use a Microsoft Active Directory account when the messaging server is in a remote Microsoft Active Directory domain. • Turn on Integrated Windows authentication when users access resources on your organization's network. Prerequisites: Configuring the Microsoft Active Directory account to delegate access to a shared folder • Verify that you configured Integrated Windows® authentication for the file server that hosts the shared folders. • Verify that you have permission to update the Microsoft® Active Directory® account in Microsoft Active Directory. • Verify that you have access to the Windows Server® setspn tool that is included with the Windows Server Support Tools. For more information about the setspn tool, visit http://technet.microsoft.com to read Setspn Overview. • If you did not configure a Microsoft Active Directory account to delegate access to an intranet site or shared folder, in Microsoft Active Directory, you must create a Microsoft Active Directory account that should have the following conditions: • the password meets the security requirements of your organization • the user is not required to change their password the next time that the user logs in • the user's password never expires Configure the Microsoft Active Directory account to delegate access to a shared folder You are required to have only one Microsoft® Active Directory® account in each Microsoft Active Directory domain that includes the resources that you want to turn on Integrated Windows® authentication for. For more information about configuring the Microsoft Active Directory account using setspn and Microsoft Active Directory, visit www.blackberry.com/btsc to read article KB22726. 1. In Microsoft Active Directory, in the Microsoft Active Directory account properties, if the Delegation tab does not display, update the default HOST SPN registrations for the Microsoft Active Directory account. 2. In the Microsoft Active Directory account properties, on the Delegation tab, configure the following settings: • trust this user for delegation to specified services only • use any authentication protocol 3. Click Add. 4. Select the the file server that hosts the shared folder. 5. Select the CIFS service type for the file server that you specified. 6. Repeat steps 3 to 5 for each shared folder that you want to turn on Integrated Windows authentication for. After you finish: 268

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

6.
Select the HTTP service type for the user account or application server that you specified.
7.
Repeat steps 1 to 6 for each intranet site that you want to turn on integrated Windows authentication for.
After you finish:
If required, configure BlackBerry® MDS Connection Service to use a Microsoft Active Directory account when
the messaging server is in a remote Microsoft Active Directory domain.
Turn on Integrated Windows authentication when users access resources on your organization's network.
Prerequisites: Configuring the Microsoft Active Directory account to delegate access
to a shared folder
Verify that you configured Integrated Windows® authentication for the file server that hosts the shared folders.
Verify that you have permission to update the Microsoft® Active Directory® account in Microsoft Active
Directory.
Verify that you have access to the Windows Server® setspn tool that is included with the Windows Server Support
Tools. For more information about the setspn tool, visit
to read
Setspn Overview
.
If you did not configure a Microsoft Active Directory account to delegate access to an intranet site or shared
folder, in Microsoft Active Directory, you must create a Microsoft Active Directory account that should have the
following conditions:
the password meets the security requirements of your organization
the user is not required to change their password the next time that the user logs in
the user's password never expires
Configure the Microsoft Active Directory account to delegate access to a shared
folder
You are required to have only one Microsoft® Active Directory® account in each Microsoft Active Directory domain
that includes the resources that you want to turn on Integrated Windows® authentication for.
For more information about configuring the Microsoft Active Directory account using setspn and Microsoft Active
Directory, visit
www.blackberry.com/btsc
to read article KB22726.
1.
In Microsoft Active Directory, in the Microsoft Active Directory account properties, if the
Delegation
tab does
not display, update the default HOST SPN registrations for the Microsoft Active Directory account.
2.
In the Microsoft Active Directory account properties, on the
Delegation
tab, configure the following settings:
trust this user for delegation to specified services only
use any authentication protocol
3.
Click
Add
.
4.
Select the the file server that hosts the shared folder.
5.
Select the CIFS service type for the file server that you specified.
6.
Repeat steps 3 to 5 for each shared folder that you want to turn on Integrated Windows authentication for.
After you finish:
Administration Guide
Configuring Integrated Windows authentication so that users can access resources on your
organization's network
268