Mechanism allowing a service, for instance Entra application proxy, to request Kerberos tickets on behalf of a user so that apps using Integrated Windows Authentication get single sign-on.
Also called KCD, KCD.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Kerberos Constrained Delegation in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra application proxy
Makes on-premises web applications reachable from outside using a connector that only makes outbound connections, so neither a VPN nor open inbound ports are required.
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- IWA
Sign-in method where domain users access apps with their existing Windows credentials over Kerberos or NTLM. To expose such apps outside the network, Microsoft Entra application proxy can publish them using Kerberos Constrained Delegation.
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- SSO
Signing in once to gain access to multiple applications.
Related terms
- CredSSP
Hyper-V can use it for live migrations instead of Kerberos constrained delegation; it works by delegating a user's entire credentials to the remote server.
- Delegated Login Identity
When single sign-on uses Kerberos Constrained Delegation through application proxy and a user's cloud name doesn't match their on-premises name, this option picks the identity the connector requests a Kerberos ticket for. Choices include the UPN and the on-premises SAM account name.
- SPN
Kerberos looks this name up to find which account a particular service instance runs as. Application proxy uses it when doing Kerberos constrained delegation to an app.