6 August,19 at 08:36 PM
Note, the "first SSO hop", is not necessarily the "first hop", for example,
In the examples below, the user account is from the trusted cross-forest, hostA and hostB are from trusting forest.
putty ----> hostA ----> hostB
(cross-forest user) putty password-login to hostA, then SSO to hostB, afterwards you cannot do another SSO from hostB
putty ---> hostA --X--> hostB
(cross-forest user) putty SSO-login to hostA, afterwards you cannot do another SSO from hostA. However, you can still do password login to hostB.
Microsoft has provided a powershell script in their KB that is referenced above. If this TGT Delegation flag needs to be reverted, consult with MS regarding any issues with the script.
Centrify Corporation does not take any responsibility for the content or availability of this link and it was provided as a courtesy. Customers should contact the vendor if there are any further questions