Export (0) Print
Expand All

Services for User to Self Configuration

Updated: November 30, 2007

Applies To: Windows Server 2008

Services for User to Self (S4USelf) provides the ability for a service to request a Kerberos ticket on behalf of a user account.

Events

Event ID Source Message

25

Microsoft-Windows-Kerberos-Key-Distribution-Center

The account %1 from domain %2 is attempting to use S4USelf for the target client %3, but is not allowed to perform group expansion on this client's user object. It may be necessary to adjust the ACL on the TokenGroupsGlobalAndUniversal attribute on the target client's user object to allow S4USelf to function correctly. This can also be accomplished by adding %1 to the Windows Authorization Access Group.

Related Management Information

Kerberos Key Distribution Center

Core Security

Was this page helpful?
(1500 characters remaining)
Thank you for your feedback

Community Additions

ADD
Show:
© 2014 Microsoft