All Attributes


ms-DS-Allowed-To-Delegate-To Attribute

This is an attribute on service account (computer or user account) objects. It contains a list of Service Principal Names (SPN). This attribute is used to configure a service to be able to obtain service tickets usable for Constrained Delegation.

CNms-DS-Allowed-To-Delegate-To
Ldap-Display-NamemsDS-AllowedToDelegateTo
Size0 to 64K
Update Privilege-
Update FrequencyInfrequently
Attribute-Id1.2.840.113556.1.4.1787
System-Id-Guid800d94d7-b7a1-42a1-b14d-7cae1423d07f
SyntaxString(Unicode)

Implementations

Windows Server 2003

Link-Id-
MAPI-Id-
System-OnlyFalse
Is-Single-ValuedFalse
Is IndexedFalse
In Global CatalogFalse
NT-Security-DescriptorO:BAG:BAD:S:
Range-Lower-
Range-Upper-
Search-Flags0x00000000
System-Flags0x00000010
Classes used inOrganizational-Person

Windows Server 2003 R2

Link-Id-
MAPI-Id-
System-OnlyFalse
Is-Single-ValuedFalse
Is IndexedFalse
In Global CatalogFalse
NT-Security-DescriptorO:BAG:BAD:S:
Range-Lower-
Range-Upper-
Search-Flags0x00000000
System-Flags0x00000010
Classes used inOrganizational-Person

Windows Server 2008

Link-Id-
MAPI-Id-
System-OnlyFalse
Is-Single-ValuedFalse
Is IndexedFalse
In Global CatalogFalse
NT-Security-DescriptorO:BAG:BAD:S:
Range-Lower-
Range-Upper-
Search-Flags0x00000000
System-Flags0x00000010
Classes used inOrganizational-Person

Send comments about this topic to Microsoft

Build date: 7/7/2009

Tags :


Page view tracker