Kerberos Delegation Question

G

Guest

We are trying to get windows authentication to work with Reporting Services
and Analysis Services in a way that may be unsupported.

Setup:

There are two domains: A and B.

There are two servers in the A domain: A\R and A\S

Server R is running Reporting Services to serve OLAP reports from data on
server S running Analysis Services.

R is trusted for delegation. Users are able to run reports from any machines
in domain A.

Domain B is trusted by Domain A.

Users have accounts on both domain A and domain B; however, for inexplicable
(beurocratic?) reasons they can access the servers in domain A only with
their domain A accounts, but can log in locally only with their domain B
accounts.

Problem:

When B\User browses to the report server, she is prompted for a user name
and password. She enters her A\UserName and password and is authenticated on
the Report Server. The report; however, (apparently) does not impersonate the
A\UserName account but instead tries to use the NT AUTHORITY\ANONYMOUS
account and fails to authenticate in Analysis Services. I'm just guessing at
the cause, but for whatever reason authentication fails.

Question:

Is it possible to get Reporting Services/IIS to impersonate users based on
the Windows credentials they entered into Internet Explorer?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,768
Messages
2,569,574
Members
45,050
Latest member
AngelS122

Latest Threads

Top