Configuring resource based Kerberos constrained delegation for the Docs service
You can configure the Docs service to use resource based Kerberos constrained delegation (KCD) to access resources, such as Microsoft SharePoint servers and File Share servers, and remove the requirement for users to provide their network credentials to access resources within the domain, and between domains and forests. When you configure resource based KCD for your Docs service, the resource authorizes the service accounts that can delegate against the resource. If you need to enable KCD in your environment, it is recommended you enable resource based KCD, if your environment meets the minimum requirements. This is also recommended in environments that do not use multiple domains or forests. If your environment does not meet the requirements for resource based KCD, you can configure Kerberos constrained delegation (KCD).
Configuring the Docs service with resource based KCD allows users to access resources in the same domain or between domains and forests.