Skip to content

Commit e3e7b70

Browse files
authored
Clarify SPN configuration for web applications.
Added note about avoiding duplicate SPNs for the same service.
1 parent ec7f0dd commit e3e7b70

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

support/developer/webapps/iis/was-service-svchost-process-operation/understanding-identities.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,8 @@ To understand application pool identities, you have to understand what an identi
9191
```console
9292
setspn -a HTTP/MyWebAppZone.com Server1$
9393
```
94-
94+
This situation results in duplicate SPNs for the same service (in this case, HTTP), where each server account has its own SPN — a configuration you should avoid.
95+
9596
To overcome this disadvantage, you can run the application under a custom Windows (domain) identity, and then set the SPN to only that specific domain account in the domain controller.
9697
9798
Registering an SPN to a domain account:

0 commit comments

Comments
 (0)