WinSecWiki > Security Settings > Local Policies > User Rights > User Rights In-Depth > Enable trusted for delegation

Enable computer and user accounts to be trusted for delegation

This powerful user right allows you to check the “Trusted for delegation” check box on computer and user accounts in Active Directory. This right has no function on member servers and workstations. To set the check box you must have this right on the domain controller to which you are currently connected with Active Directory.

The word delegation in the context of this right has nothing to do with “delegation” in the context of delegation of administrative authority in Active Directory such as with the Delegation of Control Wizard that is accessible when you right click on an Organizational Unit within Active Directory Users and Computers. 

In this context, delegation has to do with allowing server applications to use “delegated” client credentials to access other servers on behalf of that user. The “Trusted for delegation” box on user and computer accounts is intended for server applications that need this capability.

Back to top

 

Upcoming Webinars
    Additional Resources