Skip to main content

AuthNegotiateDelegateByKdcPolicy

Use KDC policy to delegate credentials. - AuthNegotiateDelegateByKdcPolicy​

Setting the policy to Enabled means HTTP authentication respects approval by KDC policy. In other words, Google Chrome delegates user credentials to the service being accessed if the KDC sets OK-AS-DELEGATE on the service ticket. See RFC 5896 ( https://tools.ietf.org/html/rfc5896.html ). The service should also be allowed by AuthNegotiateDelegateAllowlist.

Setting the policy to Disabled or leaving it unset means KDC policy is ignored on supported platforms and only AuthNegotiateDelegateAllowlist is respected.

On Microsoft® Windows®, KDC policy is always respected.

  • True = Use KDC policy approval during HTTP authentication
  • False = Ignore KDC policy approval during HTTP authentication

Data Type:

Boolean

Supported features:

  • Dynamic Policy Refresh: True
  • Per Profile: False