Blackberry PRD-10459-016 User Guide - Page 315

Configuring the Microsoft Active Directory account to delegate access

Page 315 highlights

Administration Guide Managing how users access enterprise applications and web content Configuring the Microsoft Active Directory account to delegate access Prerequisites: Configuring the Microsoft Active Directory account to delegate access to an intranet site • Verify that you configured Integrated Windows authentication for the application server that hosts the intranet site. • Verify that the application server that hosts the intranet site and the web application that runs on the application server support Kerberos authentication. • Verify that you have permission to update the Microsoft Active Directory account in Microsoft Active Directory. • Verify that you have access to the Windows Server setspn tool that is included with the Windows Server Support Tools. For more information about the setspn tool, visit http://technet.microsoft.com to read Setspn Overview. • If you did not configure a Microsoft Active Directory account to delegate access to an intranet site or shared folder, in Microsoft Active Directory, you must create a Microsoft Active Directory account that should have the following conditions: • a password that meets the security requirements of your organization • the user is not required to change their password the next time that the user logs in • the user's password never expires • If you configured a pool of application servers to host the intranet site, and the pool is running on Microsoft IIS and is located behind a load balancer, specify a user account (also known as the identity) for the pool that hosts the intranet site. For more information, see http://technet.microsoft.com/en-us/library/cc771170(WS.10).aspx. Configure the Microsoft Active Directory account to delegate access to an intranet site You are required to have only one Microsoft Active Directory account in each Microsoft Active Directory domain that includes the resources that you want to turn on Integrated Windows authentication for. For more information about configuring the Microsoft Active Directory account using setspn and Microsoft Active Directory, visit www.blackberry.com/btsc to read article KB22726. 1. If a pool of application servers host a intranet site and the pool is running on Microsoft IIS and is located behind a load-balancer, use setspn or ADSI to add the SPNs of the intranet site to the user account (also known as the identity) of the pool. You must configure the SPNs using the FQDN and the name of the intranet site that users type into their browsers (for example, if users type http://intranet_site in their browsers, the name of the intranet site is intranet_site). 315

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500

Configuring the Microsoft Active Directory account to
delegate access
Prerequisites: Configuring the Microsoft Active Directory account to
delegate access to an intranet site
Verify that you configured Integrated Windows authentication for the application server that hosts the intranet site.
Verify that the application server that hosts the intranet site and the web application that runs on the application server
support Kerberos authentication.
Verify that you have permission to update the Microsoft Active Directory account in Microsoft Active Directory.
Verify that you have access to the Windows Server setspn tool that is included with the Windows Server Support Tools.
For more information about the setspn tool, visit
to read
Setspn Overview
.
If you did not configure a Microsoft Active Directory account to delegate access to an intranet site or shared folder, in
Microsoft Active Directory, you must create a Microsoft Active Directory account that should have the following
conditions:
a password that meets the security requirements of your organization
the user is not required to change their password the next time that the user logs in
the user's password never expires
If you configured a pool of application servers to host the intranet site, and the pool is running on Microsoft IIS and is
located behind a load balancer, specify a user account (also known as the identity) for the pool that hosts the intranet
site. For more information, see
.
Configure the Microsoft Active Directory account to delegate access to an
intranet site
You are required to have only one Microsoft Active Directory account in each Microsoft Active Directory domain that
includes the resources that you want to turn on Integrated Windows authentication for.
For more information about configuring the Microsoft Active Directory account using setspn and Microsoft Active Directory,
visit
www.blackberry.com/btsc
to read article KB22726.
1.
If a pool of application servers host a intranet site and the pool is running on Microsoft IIS and is located behind a
load-balancer, use setspn or ADSI to add the SPNs of the intranet site to the user account (also known as the identity)
of the pool. You must configure the SPNs using the FQDN and the name of the intranet site that users type into their
browsers (for example, if users type http://intranet_site in their browsers, the name of the intranet site is
intranet_site).
Administration Guide
Managing how users access enterprise applications and web content
315