Article ID: 942637 - Last Review: June 20, 2008 - Revision: 2.0 A user cannot access a Web site that is published in ISA Server 2006 by using Kerberos constrained delegation if the user is not in the same domain as the ISA Server computerSYMPTOMSConsider the following scenario:
The page cannot be displayed Error Code: 403 Forbidden. The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. (12202) CAUSEISA Server does not correctly parse the domain name from the UPN credential. Instead, ISA Server uses its own domain name in the ticket-granting service (TGS) request to request a Kerberos ticket on behalf of the user. If the user belongs to a different domain, the Active Directory directory service does not know the service name. Therefore, the Active Directory directory service does not give ISA Server a ticket for authentication. RESOLUTIONTo resolve this problem, apply the hotfix rollup package that is described in the following article in the Microsoft Knowledge Base:
For more information, click the following article number to view the article in the Microsoft Knowledge Base:
942639
(http://support.microsoft.com/kb/942639/
)
Description of the ISA Server 2006 hotfix package: September 24, 2007
WORKAROUNDTo work around this problem, a user can specify a SAM-compatible user name in the credential when the user authenticates with ISA Server. A SAM-compatible user name resembles the following:
DomainName\Username
Note This workaround may still fail if the user account is a member of a domain in a trusted forest.
For more information about this limitation, click the following article number to view the article in the Microsoft Knowledge Base:
949015
(http://support.microsoft.com/kb/949015/
)
Applications that perform KCD delegation may not finish the S4U process on a computer that is running Windows Server 2008 or Windows Server 2003
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. | Article Translations
|

Back to the top
