Overview #
The TRUSTED_FOR_DELEGATION is a
user-Account-Control Attribute Value that implies when this flag is set, the service account (the user or computer account) under which a service runs is trusted for
Kerberos delegation as described in
SECURITY_IMPERSONATION_LEVEL. Any such
service can obtain a
Impersonation Token on behalf of a
client requesting the service. To enable a service for
Kerberos Delegation, you must set this flag on the
user-Account-Control Attribute Value property of the service account.
There might be more information for this subject on one of the following: