-After setting up the previous steps correctly, the next step is to create the HDInsight cluster with ESP enabled. When you create an HDInsight cluster, you can enable Enterprise Security Package in the **Security + networking** tab. If you prefer to use an Azure Resource Manager template for deployment, use the portal experience once and download the pre-filled template on the **Review + create** page for future reuse. The [HDInsight ID Broker](https://docs.microsoft.com/en-us/azure/hdinsight/domain-joined/identity-broker) feature can also be enabled during cluster creation. The ID Broker feature lets you sign in to Ambari using MFA and get the required Kerberos tickets without needing password hashes in Azure Active Directory Domain Services (AAD-DS).
0 commit comments