Untitled

  1. A user - Joe, authenticates to the web service (running with service account websvc) using a non-Kerberos compatible authentication mechanism.
  2. The web service requests a ticket from the Key Distribution Center (KDC) for Joe's account without supplying a password, as the websvc account.
  3. The KDC checks the websvc userAccountControl value for the TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION attribute, and that Joe's account is not blocked for delegation. If OK it returns a forwardable ticket for Joe's account (S4U2Self).
  4. The service then passes this ticket back to the KDC and requests a service ticket for the CIFS/dcorpmssql.dollarcorp.moneycorp.local service.
  5. The KDC checks the msDS-AllowedToDelegate To field on the websvc account. If the service is listed it will return a service ticket for dcorp-mssql (S4U2Proxy).
  6. The web service can now authenticate to the CIFS on dcorpmssql as Joe using the supplied TGS.
Get-DomainUser –TrustedToAuth
Get-DomainComputer –TrustedToAuth