Question 1
A financial services company is implementing Kerberos-based Single Sign-On (SSO) for its SAP S/4HANA landscape. During testing, users in a trusted domain can log on seamlessly, but users from a newly acquired company in a separate forest fail to authenticate. The network firewalls are confirmed to be open. Which of the following is the most critical configuration to check for resolving cross-forest authentication issues?
Answer and explanation
Correct answer: B
For Kerberos authentication to work across different Active Directory forests, a proper two-way forest trust must be established. Furthermore, if 'selective authentication' is enabled on the trust, the service account running the SAP application server must be explicitly granted the 'Allowed to Authenticate' permission on the domain controllers of the other forest. This is a common point of failure in complex multi-forest Kerberos setups.