Kerberos delegation lets a front-end service reach a back-end service as the user who authenticated to the front end. Choose constrained delegation when the front end should reach only named services; consider resource-based constrained delegation (RBCD) when the back-end resource should control which front ends it trusts, especially across domain or forest trust boundaries. Avoid unconstrained delegation except for a documented legacy dependency.
What Kerberos delegation does
In a multi-tier application, a user may authenticate to a front-end service that then needs to access a back-end service using that user’s identity. Delegation is the mechanism that allows this second service-to-service hop to occur on the user’s behalf. The front end, the domain controller’s Key Distribution Center (KDC), and the back end all participate in the identity flow; it is not simply a matter of forwarding the user’s password.
For constrained delegation, Microsoft documents S4U2Proxy as the protocol extension a service uses to obtain a service ticket for a back-end service. The front end’s delegation permissions determine which destinations are allowed. The KDC and service principal name (SPN) configuration therefore matter as much as the application’s authentication settings.
Unconstrained, constrained, and resource-based delegation
The key distinction is which account holds the delegation allow-list and how narrowly that list limits the front end’s reach.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- 𝗢𝗻𝗲 𝗦𝘄𝗶𝘁𝗰𝗵 𝗠𝗮𝗱𝗲 𝘁𝗼 𝗘𝘅𝗽𝗮𝗻𝗱 𝗡𝗲𝘁𝘄𝗼𝗿𝗸: 5× 10/100/1000Mbps RJ45 Ports supporting Auto Negotiation and Auto MDI/MDIX.
- 𝗚𝗶𝗴𝗮𝗯𝗶𝘁 𝘁𝗵𝗮𝘁 𝗦𝗮𝘃𝗲𝘀 𝗘𝗻𝗲𝗿𝗴𝘆: Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money.
- 𝗥𝗲𝗹𝗶𝗮𝗯𝗹𝗲 𝗮𝗻𝗱 𝗤𝘂𝗶𝗲𝘁: IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation.
- 𝗣𝗹𝘂𝗴 𝗮𝗻𝗱 𝗣𝗹𝗮𝘆: Easy setup with no software installation or configuration needed.
- 𝗔𝗱𝘃𝗮𝗻𝗰𝗲𝗱 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗙𝗲𝗮𝘁𝘂𝗿𝗲𝘀: Prioritize your traffic and guarantee high quality of video or voice data transmission with Port-based 802.1p/DSCP QoS and IGMP Snooping.
| Model | Where permission is defined | Scope and typical topology | Security implications and use |
|---|---|---|---|
| Unconstrained delegation | On the front-end account or computer | Can permit access to any Kerberos service in the domain | Broadest exposure; treat as a legacy dependency and avoid for new designs. |
| Constrained delegation (KCD) | On the front-end account, which lists permitted back-end service SPNs | Limited to the specified services; commonly used when a front end accesses known back ends in the same domain | Narrower than unconstrained delegation. The front end’s configured allow-list controls the destinations. |
| Resource-based constrained delegation (RBCD) | On the back-end resource account, which identifies permitted front ends | Limited to front ends named by that resource; useful in cross-domain or cross-forest trusted service paths | Lets the resource owner control which front ends may delegate to it. It still requires correct identity, SPN, and trust configuration. |
Microsoft describes constrained delegation as a safer form of delegation than the unconstrained model. “Safer” does not mean risk-free: a compromised front end may still act as users toward the services it is permitted to reach.
Protocol transition: when the first hop is not Kerberos
Protocol transition is relevant when the user-facing application accepts a non-Kerberos authentication method but must use Kerberos for a downstream feature, such as mutual authentication or constrained delegation. In that design, the front end transitions to Kerberos for the onward request. It is a separate design choice from the list of back-end services the front end may access.
Rank #2
- GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
In classic constrained delegation, the “Use any authentication protocol” setting enables protocol transition. Do not enable it simply to make a failing second hop work: first establish that the application needs a non-Kerberos first hop, then assess the added trust boundary and restrict destinations. A Kerberos-authenticated first hop does not by itself mean protocol transition is required.
Choosing a delegation model
- Prefer classic constrained delegation when a front end in a known same-domain design needs access to a defined set of back-end SPNs and the front-end owner can manage that allow-list.
- Consider RBCD when the back-end resource owner should decide which front ends may act on behalf of users, particularly for a cross-domain or cross-forest path with the required trust in place.
- Retain unconstrained delegation only when an identified legacy dependency cannot yet be removed and its exposure is explicitly accepted and controlled.
- Use protocol transition only when needed for the application’s authentication flow; it does not replace destination scoping.
Do not configure classic constrained delegation and RBCD simultaneously for the same front-end/back-end path without understanding the KDC’s selection behavior. Microsoft’s troubleshooting guidance says the KDC checks classic constrained delegation on the front end first and checks RBCD on the resource only when classic constrained delegation is not configured. Conflicting or unexpected settings can therefore make an intended RBCD configuration ineffective.
Rank #3
- GIGABIT ETHERNET PORTS: Features 8 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
Diagnosing a Kerberos double-hop or second-hop failure
A second-hop failure is a symptom, not proof that delegation is the only problem. Confirm the topology and the identities actually used by the services before changing permissions. Work through these checks in order:
- Map the path. Identify the user-facing service, its running identity, the back-end service, and whether they are in the same domain, different domains, or forests connected by a trust. Cross-domain or trusted-forest paths often point toward evaluating RBCD, but the trust and service configuration still have to support the requested path.
- Confirm the front-end identity. Establish whether the service runs as a built-in computer or service account, a managed service account, or a custom account. Verify that the account configured for delegation is the account the process actually uses.
- Check names and SPNs. Verify DNS and name resolution, and confirm that each requested back-end SPN exists and maps to the intended account. Missing or duplicate SPNs can prevent Kerberos from issuing the expected ticket, even when delegation permissions appear correct.
- Inspect delegation settings. For classic constrained delegation, confirm that the front-end account’s allowed SPNs match the back-end service being requested. For RBCD, confirm that the resource account allows the intended front-end principal. Check whether protocol transition is enabled only if the application needs it.
- Check domain-controller update state. Review patch and enforcement status across the domain controllers involved. Microsoft’s CVE-2020-16996 guidance warns that a mix of updated and older KDCs can deny protocol transition. Its CVE-2020-17049 guidance requires domain-controller updates for corrected S4U delegation validation.
- Retest with least privilege. Test the intended path with a non-privileged account, then inspect the Kerberos tickets and relevant events. Do not use broad unconstrained delegation in production as a diagnostic shortcut.
Reducing delegation risk
Unconstrained delegation is especially dangerous because a compromised delegated host may retain TGT material that can be used to impersonate users to Kerberos-protected services. Microsoft’s 2025 Active Directory security guidance characterizes the feature as legacy and recommends removing unnecessary unconstrained delegation.
Rank #4
- 8 GIGABIT PORTS: Features 8 RJ45 ports supporting 10/100/1000 Mbps speeds, providing high-speed wired network connectivity for computers, printers, gaming consoles, and other Ethernet-enabled devices
- PLUG AND PLAY SETUP: No configuration required; simply connect the switch to your network devices and it is ready to use immediately, making network expansion quick and hassle-free
- FANLESS QUIET DESIGN: The fanless design ensures silent operation, making this switch suitable for noise-sensitive environments such as home offices, bedrooms, or conference rooms
- STURDY METAL CONSTRUCTION: Built with a durable metal housing and shielded ports that provide reliable performance, better heat dissipation, and protection against electromagnetic interference
- TRAFFIC OPTIMIZATION: Supports IEEE 802.3x flow control and advanced traffic optimization technology to reduce data bottlenecks and ensure smooth, efficient data transfer across your network
- Inventory systems configured for unconstrained delegation and remove it where no documented dependency remains.
- Use Credential Guard where applicable, and protect privileged accounts from exposure to delegated hosts.
- Mark high-risk identities as sensitive and not delegable where appropriate.
- Across incoming trusts, use Microsoft’s controls to block TGT delegation at the forest boundary and move toward constrained or resource-based constrained delegation where the service design allows it.
Delegation permissions define a trust boundary: compromising a front end with permission to act for users can expose the services within its permitted scope. Limiting that scope, protecting the service identity, and keeping domain controllers consistently updated are complementary controls.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.PowerShell inspection and configuration scope
Microsoft identifies Get-ADComputer, Get-ADServiceAccount, and Get-ADUser for inspecting relevant account settings, and the corresponding Set-ADComputer, Set-ADServiceAccount, and Set-ADUser cmdlets for setting the principals-allowed configuration used by RBCD. Use the cmdlet that matches the actual resource or front-end account type, and verify the resulting configuration on the intended account. The correct cmdlet alone cannot compensate for a wrong principal, SPN, or trust path.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Best Value
- Expand Your Network: UGREEN ethernet switch with 5 RJ45 ports has indicator lights, support automatic adjustment to the network speed of 10/100/1000Mbps, support full duplex and half duplex modes, and support automatic MDI/MDIX flip function
- Wide Application: UGREEN gigabit ethernet switch supports Windows/macOS/Linux/Android/iOS systems, suitable for schools, private homes, offices of micro-enterprises, security monitoring and other places
- Plug and Play: UGREEN unmanaged ethernet switch is no driver required and easy to use, ensures a smooth connection with multiple devices. (POE is not supported)
- Easy Installation: UGREEN ethernet hub can be placed on the desk for use; there are wall mounting holes on the back, which can be hung on the wall to save space
- High Efficiency & Energy Saving: UGREEN ethernet splitter complies with IEEE802.3/u/x/ab standards, and adopts fanless design to ensure silent operation, environmental protection and reduction of energy consumption
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

