Strong Authentication (SASL) Permissions

For Strong authentication (SASL), a single service account can be used for multiple domains/forests.

Prerequisites

  • The domains must have two-way trust.

  • The service account must have delegated permissions across other domains for user, contact, and group objects.

    Permissions must be delegated to the service account. Use the Delegation Control Wizard to delegate permissions to the contact.

To delegate permissions using the Delegation Control Wizard, complete the following:

  1. Open Active Directory Users and Computers.

  2. Right-click on the Domain and select Delegate Control to open Delegation of Control Wizard and then select Next.

  3. Select the Add button to add a service account user and then select Next.

  4. Select Create a custom task to delegate and then select Next.

  5. Only select the following objects in the folder option: User Objects, Contact Objects, Group Objects, and Create/Delete the selected objects in the folder.

  6. On the next screen, under Permissions select Full Control, then select Next.

  7. Select Finish.