Health check › Apps and files
File shares: delegation
Check id files.delegation
What it checks
To open a file share as a person, Gate needs Active Directory's permission to ask for that person's ticket to the file server (constrained delegation with protocol transition), limited to your file servers and domain controllers. Windows edition: the server's computer account. Linux appliance: gate-svc.
What you might see
| Problem | Computer account GATE1$ may not act for people who signed in without Kerberos (protocol transition is off). | "Use any authentication protocol" is not set. |
| Problem | Gate server GATE1$ may not delegate to: cifs/fs1.corp.example, cifs/fs1. | A file server is missing from the allowed list. |
| OK | GATE1$ may open 3 server(s) and DC(s) as people (constrained delegation + protocol transition). | Fine. |
How to fix it
- In Active Directory Users and Computers, open the Gate server's computer account (Linux appliance: the
gate-svcuser) → Delegation tab. - Choose Trust this computer for delegation to specified services only and Use any authentication protocol.
- Add → Users or Computers → each file server and domain controller → select the cifs service.
- Security tip from the same check: mark admin accounts Account is sensitive and cannot be delegated (user → Account tab), so no service can ever act as them.
Command line (on a DC, Windows edition)
Set-ADAccountControl -Identity GATE1$ -TrustedToAuthForDelegation $true
Set-ADComputer -Identity GATE1$ -Add @{'msDS-AllowedToDelegateTo'=@('cifs/fs1.corp.example','cifs/fs1')}
Set-ADUser -Identity admin.jane -AccountNotDelegated $true
Command line (on a DC, Linux appliance)
Set-ADAccountControl gate-svc -TrustedToAuthForDelegation $true
Set-ADUser gate-svc -Add @{'msDS-AllowedToDelegateTo'=@('cifs/fs1.corp.example','cifs/fs1')}Related checks
File shares: service brokerShare (each mapped drive)
Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides
Acutis