How Can We Help?
< All Topics
Print

Hyper-V Kerberos Constrained Delegation Mastery: A Comprehensive Guide

Kerberos, the default Active Directory authentication protocol, offers single-hop credential transmission but can pose security risks. Constrained delegation can mitigate this by limiting the use of account credentials.

a) How do I enable Kerberos-constrained delegation in Hyper-V ?

1. First, open the Active Directory Users and Computers (ADUC) console from any domain controller in the Active Directory domain to access the default container named “Computers”.

Hyper-V

2. Then, select the computer (Hyper-V host server) on which you want to configure constrained delegation, right-click it, and select Properties.

3. After that, navigate to the delegation tab.

4. Next, select the Trust this computer for delegation to specified services only option and ensure the Use Kerberos only option is selected.

5. Finally, click Add and select the Hyper-V target host in the Services box. From the list of services, choose the following services:

  • cifs (user for file sharing access)
  • Microsoft Virtual System Migration Service

Table of Contents