To enable delegation for Federated Authentication, follow the steps.

To enable delegation for Federated Authentication

  1. Open the Active Directory Users and Computers tool.

  2. Open the properties of the Federated Authentication domain service account and click on the Delegation tab.

  3. Select Trust this user for delegation to specified services only.

  4. Ensure Use any authentication protocol is selected.

  5. Click Add.

  6. Click Users or Computers.

  7. Enter the name of the Federated Authentication domain service account and click OK.

    The ARAdminSvc and HTTP Service Types are displayed for the short name of the Active Roles server.

  8. Click Select All.

  9. Click OK. The Service Types are now listed.

  10. To see the FQDN Service Types, select the Expanded check box. Click OK.

    Figure 10: Delegation settings of the Federated Authentication domain service account

  11. Close the Active Directory Users and Computers tool and log off the Domain Controller.