Alternatively, you can specify the identifier impersonate = true in the web.config file, and the Active Directory directory request will be sent as the calling user instead of Machine \ ASPNET
Edit: if you get an authentication error, see the PIPTHEGEEK message, you need to trust the web server for delegation, but be careful with the delegation trust (since it opens another can of worms for security types). You must allow the web server to transfer the credentials of the current AD user.
If possible, go to the AD properties for the computer, select the delegation tab and select "Trust this computer to delegate to any service (Kerberos only)
See if this works. If so, you can further clear permissions using the third option, which states
"Trust this computer only to delegate only the specified services"
Then select Use Only Kerberos
and in the "Services for which this account can provide delegated credentials", add the appropriate service information.
kd7
source share