Hyper-V can use it for live migrations instead of Kerberos constrained delegation; it works by delegating a user's entire credentials to the remote server.
Also called Credential Security Support Provider.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains CredSSP in context, with comparison tables and the common traps.
Terms in this definition
- Hyper-V
The hypervisor built into Windows. The VMs for the Azure Extended Network appliance require the Hyper-V role, using nested virtualisation, and an external virtual switch for each NIC.
- Kerberos Constrained Delegation
Mechanism allowing a service, for instance Entra application proxy, to request Kerberos tickets on behalf of a user so that apps using Integrated Windows Authentication get single sign-on.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
Related terms
- Credential Guard
Uses virtualisation-based security to isolate Kerberos TGTs and NTLM hashes. Windows Server 2025 enables it automatically on domain-joined member servers (not DCs), which breaks live migration relying on CredSSP.
- Protected Users
Members get fixed protections: four-hour TGTs, no delegation, no Digest, CredSSP or NTLM, and no RC4 or DES during Kerberos pre-authentication. Keep computer and service accounts out of this global group.