{"id":19452,"date":"2023-07-17T15:43:48","date_gmt":"2023-07-17T19:43:48","guid":{"rendered":"https:\/\/kevinjustin.com\/blog\/?p=19452"},"modified":"2024-09-10T13:42:46","modified_gmt":"2024-09-10T17:42:46","slug":"scom-webconsole-settings-for-kerberos-ad-delegation","status":"publish","type":"post","link":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/","title":{"rendered":"SCOM WebConsole settings for Kerberos AD Delegation"},"content":{"rendered":"<figure id=\"attachment_19453\" aria-describedby=\"caption-attachment-19453\" style=\"width: 525px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19453\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg\" alt=\"Kerberos AD delegation as the Navajo and Comanche helped allies in WW2, encrypted and encoded communication\" width=\"525\" height=\"477\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg 525w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers-300x273.jpg 300w\" sizes=\"auto, (max-width: 525px) 85vw, 525px\" \/><\/a><figcaption id=\"caption-attachment-19453\" class=\"wp-caption-text\">I attribute Kerberos AD delegation as the Navajo and Comanche helped allies in WW2, encrypted and encoded communication<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Next on the list is to setup SCOM WebConsole settings for Kerberos AD Delegation.\u00a0 I attribute Kerberos AD delegation as the Navajo and Comanche helped allies in WW2, encrypted and encoded communication.\u00a0 Time to make the donuts! (to setup SCOM WebConsole settings for Kerberos AD Delegation)<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>If you&#8217;re improperly setup &#8211; you&#8217;ll flag on STIG configs V-243470, V-243478<\/p>\n<p>&nbsp;<\/p>\n<h1><strong> Documentation<\/strong><\/h1>\n<p><a href=\"https:\/\/www.sentinelone.com\/blog\/detecting-unconstrained-delegation-exposures-in-ad-environment\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.sentinelone.com\/blog\/detecting-unconstrained-delegation-exposure<\/a><\/p>\n<p><a href=\"https:\/\/pentestlab.blog\/2022\/03\/21\/unconstrained-delegation\/\" target=\"_blank\" rel=\"noopener\">https:\/\/pentestlab.blog\/2022\/03\/21\/unconstrained-delegation\/<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Outline<\/strong><\/h1>\n<p>Assess affected unconstrained delegation servers in environment<\/p>\n<p>Configure delegation on SCOM and\/or PowerBI servers<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Assess affected unconstrained delegation servers in environment<\/strong><\/h1>\n<p>From a computer, with ADUC, and RSAT feature installed, search for relevant account(s) used (Read Only RO access displayed below).<\/p>\n<figure id=\"attachment_19461\" aria-describedby=\"caption-attachment-19461\" style=\"width: 774px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/SCOM-ADUC-Screenshot-for-delegation-before.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19461\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/SCOM-ADUC-Screenshot-for-delegation-before.png\" alt=\"ADUC SCOM account examples\" width=\"774\" height=\"470\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/SCOM-ADUC-Screenshot-for-delegation-before.png 774w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/SCOM-ADUC-Screenshot-for-delegation-before-300x182.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/SCOM-ADUC-Screenshot-for-delegation-before-768x466.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19461\" class=\"wp-caption-text\">ADUC SCOM account examples<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Alternatively, from PowerShell &gt; run this command to see affected servers (much wider list, unless you add a where clause)<\/p>\n<p class=\"contentpasted0\" style=\"margin-left: 27.0pt;\"><span style=\"color: #686868; background: white;\">Get-ADComputer -LDAPFilter<\/span><\/p>\n<p class=\"contentpasted0\" style=\"margin-left: 27.0pt;\"><span style=\"color: #686868; background: white;\">&#8220;(userAccountControl:1.2.840.113556.1.4.803:=524288)&#8221;<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Configure delegation on SCOM and\/or PowerBI servers<\/strong><\/h1>\n<p>Take the list of affected servers, to take action.\u00a0 Use the steps below to configure relevant SCOM or PowerBI servers.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Configure SCOM Web Console server<\/strong><br \/>\nWith domain administrator (DA or Tier0) rights, open the Active Directory Users and Computers MMC snap-in.<\/p>\n<p>&nbsp;<\/p>\n<p>From ADUC &gt; change &#8216;Find&#8217; drop-down to Computers<\/p>\n<p>In the Computer name text box, enter &lt;SCOMWebConsoleServerName&gt;\u00a0 and\u00a0 click search<\/p>\n<p>Right click the server in the results box &gt; Select Properties.<\/p>\n<p>Select the Delegation tab.<\/p>\n<p>Select Trust this computer for delegation to specified services only &gt; Use any authentication protocol.<\/p>\n<p>Under Services to which this account can present delegated credentials, select Add.<\/p>\n<p>In the new dialog box, select Users or Computers.<\/p>\n<p>Enter &lt;SCOMWebConsoleServerName&gt;, and then select OK.<\/p>\n<p>Click the Add button to add services<\/p>\n<p>Select the <strong>w3sv<\/strong>c and <strong>www<\/strong> processes<\/p>\n<p>Select OK.<\/p>\n<p><a style=\"font-weight: bold; font-size: 0.8125rem; font-style: italic;\" href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19463\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS.png\" alt=\"ADUC SCOM Lab server choosing process\" width=\"796\" height=\"552\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS.png 796w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS-300x208.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS-768x533.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<p>ADUC SCOM Lab server choosing process<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Verification of delegation settings<\/strong><\/h2>\n<figure id=\"attachment_19464\" aria-describedby=\"caption-attachment-19464\" style=\"width: 1045px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS-After.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19464\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS-After.png\" alt=\"ADUC Delegation flags with SCOM MS processes selected.\" width=\"1045\" height=\"529\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS-After.png 1045w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS-After-300x152.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS-After-1024x518.png 1024w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-SCOMMS-After-768x389.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-19464\" class=\"wp-caption-text\">ADUC Delegation flags with SCOM MS processes selected.<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Depending on replication times for the forest, wait and later reboot &lt;SCOMWebConsoleServerName&gt; to have settings take effect.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>PowerBI Report Server<\/strong><\/h1>\n<p>With domain administrator (DA or Tier0) rights, open the (ADUC) Active Directory Users and Computers MMC snap-in.\u00a0 <span style=\"color: #ff0000;\"><strong>NOTE: RSAT tools recommended to be installed on SCOM Management Server(s)<\/strong><\/span><\/p>\n<p>In the Search text box, enter PowerBI service account &lt;Example can be SCOMDataAccessReader Account&gt; and click search<\/p>\n<p>Right-click the PowerBI service account &lt;Example can be SCOMDataAccessReader Account&gt;,\u00a0 select Properties.<\/p>\n<p>Select the Delegation tab.<\/p>\n<p>Select Trust this computer for delegation to specified services only &gt; Use any authentication protocol.<\/p>\n<p>Under Services to which this account can present delegated credentials, select Add.<\/p>\n<p>In the new dialog box, select Users or Computers.<\/p>\n<p>Enter the service account for the data source, and then select OK.<\/p>\n<p>Select the SPN that you created for &lt;PowerBI Report Server Name&gt;<\/p>\n<p>Select both as FQDN and the NetBIOS names are in the SPN<\/p>\n<p>Select OK.<\/p>\n<p>&nbsp;<\/p>\n<p>Back to ADUC (AD Users and Computers), change Find drop-down to Computers<\/p>\n<p>Enter &lt;PowerBI Report Server Name&gt;, and click search<\/p>\n<p>Right click the server in the results box &gt; Select Properties.<\/p>\n<p>Select the Delegation tab.<\/p>\n<p>Select Trust this computer for delegation to specified services only &gt; Use any authentication protocol.<\/p>\n<p>Under Services to which this account can present delegated credentials, select Add.<\/p>\n<p>In the new dialog box, select Users or Computers.<\/p>\n<p>Enter &lt;Example can be SCOMDataAccessReader Account&gt;, and then select OK.<\/p>\n<p>Click the Add button to add services<\/p>\n<p>Select the HTTP process<\/p>\n<figure id=\"attachment_20442\" aria-describedby=\"caption-attachment-20442\" style=\"width: 289px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-Delegation-AddServices.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-20442\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-Delegation-AddServices-289x300.png\" alt=\"\" width=\"289\" height=\"300\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-Delegation-AddServices-289x300.png 289w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-Delegation-AddServices.png 413w\" sizes=\"auto, (max-width: 289px) 85vw, 289px\" \/><\/a><figcaption id=\"caption-attachment-20442\" class=\"wp-caption-text\">ADUC Delegation Add Services &gt; HTTP, WWW<\/figcaption><\/figure>\n<p>Select OK.<\/p>\n<div class=\"mceTemp\"><\/div>\n<figure id=\"attachment_20440\" aria-describedby=\"caption-attachment-20440\" style=\"width: 459px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-PowerBIRS-After-Copy.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-20440 size-full\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-PowerBIRS-After-Copy.png\" alt=\"ADUC Delegation Settings for http for PowerBI Report Server (PBIRS)\" width=\"459\" height=\"528\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-PowerBIRS-After-Copy.png 459w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/ADUC-DelegationSettings-PowerBIRS-After-Copy-261x300.png 261w\" sizes=\"auto, (max-width: 459px) 85vw, 459px\" \/><\/a><figcaption id=\"caption-attachment-20440\" class=\"wp-caption-text\">ADUC Delegation Settings for http for PowerBI Report Server (PBIRS)<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Next on the list is to setup SCOM WebConsole settings for Kerberos AD Delegation.\u00a0 I attribute Kerberos AD delegation as the Navajo and Comanche helped allies in WW2, encrypted and encoded communication.\u00a0 Time to make the donuts! (to setup SCOM WebConsole settings for Kerberos AD Delegation) &nbsp; &nbsp; If you&#8217;re improperly setup &#8211; you&#8217;ll &hellip; <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;SCOM WebConsole settings for Kerberos AD Delegation&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[637,2,5,636,530],"tags":[20,631,26,639,640,642,641,611,635,600,287,342,633,638,536,537],"class_list":["post-19452","post","type-post","status-publish","format-standard","hentry","category-active-directory","category-administration","category-best-practice","category-iis","category-scom","tag-active-directory","tag-ad-delegation","tag-adds","tag-aduc","tag-cac","tag-client-certificate","tag-common-access-card","tag-iis","tag-iismanager","tag-kerberos","tag-operations-manager","tag-scom","tag-smart-card","tag-web","tag-web-console","tag-webconsole"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SCOM WebConsole settings for Kerberos AD Delegation - Kevin Justin&#039;s Blog<\/title>\n<meta name=\"description\" content=\"This blog post is a &#039;how to&#039; setup SCOM WebConsole settings for Kerberos AD Delegation for secure authentications\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SCOM WebConsole settings for Kerberos AD Delegation - Kevin Justin&#039;s Blog\" \/>\n<meta property=\"og:description\" content=\"This blog post is a &#039;how to&#039; setup SCOM WebConsole settings for Kerberos AD Delegation for secure authentications\" \/>\n<meta property=\"og:url\" content=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/\" \/>\n<meta property=\"og:site_name\" content=\"Kevin Justin&#039;s Blog\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-17T19:43:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-10T17:42:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg\" \/>\n<meta name=\"author\" content=\"WordPress Administrator\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"WordPress Administrator\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/\"},\"author\":{\"name\":\"WordPress Administrator\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\"},\"headline\":\"SCOM WebConsole settings for Kerberos AD Delegation\",\"datePublished\":\"2023-07-17T19:43:48+00:00\",\"dateModified\":\"2024-09-10T17:42:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/\"},\"wordCount\":665,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/Kerberos-Code-Talkers.jpg\",\"keywords\":[\"Active Directory\",\"AD Delegation\",\"ADDS\",\"ADUC\",\"CAC\",\"Client Certificate\",\"Common Access Card\",\"IIS\",\"iisManager\",\"kerberos\",\"operations manager\",\"SCOM\",\"smart card\",\"Web\",\"web console\",\"webconsole\"],\"articleSection\":[\"Active Directory\",\"Administration\",\"Best Practice\",\"IIS\",\"SCOM\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/\",\"name\":\"SCOM WebConsole settings for Kerberos AD Delegation - Kevin Justin&#039;s Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/Kerberos-Code-Talkers.jpg\",\"datePublished\":\"2023-07-17T19:43:48+00:00\",\"dateModified\":\"2024-09-10T17:42:46+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\"},\"description\":\"This blog post is a 'how to' setup SCOM WebConsole settings for Kerberos AD Delegation for secure authentications\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/#primaryimage\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/Kerberos-Code-Talkers.jpg\",\"contentUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/Kerberos-Code-Talkers.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-kerberos-ad-delegation\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SCOM WebConsole settings for Kerberos AD Delegation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/\",\"name\":\"Kevin Justin&#039;s Blog\",\"description\":\"Operational monitoring tools including System Center, Azure Monitor\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\",\"name\":\"WordPress Administrator\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"caption\":\"WordPress Administrator\"},\"sameAs\":[\"https:\\\/\\\/kevinjustin.com\"],\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/author\\\/wordpress_admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SCOM WebConsole settings for Kerberos AD Delegation - Kevin Justin&#039;s Blog","description":"This blog post is a 'how to' setup SCOM WebConsole settings for Kerberos AD Delegation for secure authentications","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/","og_locale":"en_US","og_type":"article","og_title":"SCOM WebConsole settings for Kerberos AD Delegation - Kevin Justin&#039;s Blog","og_description":"This blog post is a 'how to' setup SCOM WebConsole settings for Kerberos AD Delegation for secure authentications","og_url":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/","og_site_name":"Kevin Justin&#039;s Blog","article_published_time":"2023-07-17T19:43:48+00:00","article_modified_time":"2024-09-10T17:42:46+00:00","og_image":[{"url":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg","type":"","width":"","height":""}],"author":"WordPress Administrator","twitter_card":"summary_large_image","twitter_misc":{"Written by":"WordPress Administrator","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/#article","isPartOf":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/"},"author":{"name":"WordPress Administrator","@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508"},"headline":"SCOM WebConsole settings for Kerberos AD Delegation","datePublished":"2023-07-17T19:43:48+00:00","dateModified":"2024-09-10T17:42:46+00:00","mainEntityOfPage":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/"},"wordCount":665,"commentCount":0,"image":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/#primaryimage"},"thumbnailUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg","keywords":["Active Directory","AD Delegation","ADDS","ADUC","CAC","Client Certificate","Common Access Card","IIS","iisManager","kerberos","operations manager","SCOM","smart card","Web","web console","webconsole"],"articleSection":["Active Directory","Administration","Best Practice","IIS","SCOM"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/","url":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/","name":"SCOM WebConsole settings for Kerberos AD Delegation - Kevin Justin&#039;s Blog","isPartOf":{"@id":"https:\/\/kevinjustin.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/#primaryimage"},"image":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/#primaryimage"},"thumbnailUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg","datePublished":"2023-07-17T19:43:48+00:00","dateModified":"2024-09-10T17:42:46+00:00","author":{"@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508"},"description":"This blog post is a 'how to' setup SCOM WebConsole settings for Kerberos AD Delegation for secure authentications","breadcrumb":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/#primaryimage","url":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg","contentUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Kerberos-Code-Talkers.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/kevinjustin.com\/blog\/"},{"@type":"ListItem","position":2,"name":"SCOM WebConsole settings for Kerberos AD Delegation"}]},{"@type":"WebSite","@id":"https:\/\/kevinjustin.com\/blog\/#website","url":"https:\/\/kevinjustin.com\/blog\/","name":"Kevin Justin&#039;s Blog","description":"Operational monitoring tools including System Center, Azure Monitor","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/kevinjustin.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508","name":"WordPress Administrator","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","caption":"WordPress Administrator"},"sameAs":["https:\/\/kevinjustin.com"],"url":"https:\/\/kevinjustin.com\/blog\/author\/wordpress_admin\/"}]}},"_links":{"self":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/comments?post=19452"}],"version-history":[{"count":12,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19452\/revisions"}],"predecessor-version":[{"id":20443,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19452\/revisions\/20443"}],"wp:attachment":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/media?parent=19452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/categories?post=19452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/tags?post=19452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}