AuthNegotiateDelegateByKdcPolicy
Use KDC policy to delegate credentials. - AuthNegotiateDelegateByKdcPolicy
Setting the policy to Enabled means HTTP authentication respects approval by KDC policy. In other words, Google Chrome delegates user credentials to the service being accessed if the KDC sets OK-AS-DELEGATE on the service ticket. See RFC 5896 ( https://tools.ietf.org/html/rfc5896.html ). The service should also be allowed by AuthNegotiateDelegateAllowlist.
Setting the policy to Disabled or leaving it unset means KDC policy is ignored on supported platforms and only AuthNegotiateDelegateAllowlist is respected.
On Microsoft® Windows®, KDC policy is always respected.
- True = Use KDC policy approval during HTTP authentication
- False = Ignore KDC policy approval during HTTP authentication
Data Type:
Boolean
Supported features:
- Dynamic Policy Refresh: True
- Per Profile: False