Service Principal Name (SPN) checklist for Kerberos authentication with IIS 7.0/7.Most CRM deployments require using both host headers and SSL certificates.
This is explained in the following article: Set the proper SPNs for the Service Account running the CRMAppPool. Then compress all of the elements under so you can see all of the main elements:Įxpand the system.webServer element and make your modifications within here.ģ. To determine which element you should be modifying, load the nfig file in Visual Studio. NOTE: There are a lot of different system.webServer references within the nfig file.
Modify the system.webServer tag to include useAppPoolCredentials: %SystemDrive%/Windows/System32/inetsrv/configī. On the Microsoft Dynamics CRM server(s), go to: Modify the nfig file for IIS to useAppPoolCredentials:Ī.
Right-click on Windows Authentication and go to Advanced Settingsį. Check "Enable Kernel-mode authentication"Ģ. Within the Features view, double click on AuthenticationĮ.
On the Microsoft Dynamics CRM server(s), open up IIS Manager:ĭ. To correct this issue, go through the following:Ī. In situations where you require the use of SPNs, such as Load Balancing, you must modify the nfig file to useAppPoolCredentials. Kernel mode authentication must be enabled. Kernel mode authentication within Internet Information Systems is disabled for the Microsoft Dynamics CRM website Resolution When you access Microsoft Dynamics CRM 2011, you are continously prompted with credentials when Microsoft Dynamics CRM is trying to access web resources.