Naked Impersonation Struggles

I am absolutely getting my a** kicked by “naked impersonation”, wondering if there’s anyone who could provide a step-by-step guide for how to set it up. I have followed the docs (link) but they were a bit confusing, seemed as though the terms shifted a few times and some of the screenshots are “off”. Then I Googled around and saw quite a few blog posts, topics, etc. indicating the docs are not accurate. I’ve also searched the issues and PRs in Github (and tried to leverage an updated screenshot that’ll be in an upcoming release), and just generally tried literally every option I can think of to try. Unfortunately I’m endlessly getting a 403/“Client not allowed to exchange” error, in the logs the message is “Client not allowed to impersonate”. I’ve been at this ~16 hours and I’m getting nowhere.
FWIW I’m able to successfully do an internal-to-internal exchange, it feels like I should be able to make the impersonation work…I’m probably closer than I think but at this point I’m about ready to kick my PC across the room.

1 Like

Same thing here - solved a lot of issues (some badly documented stuff also) but I’m stuck at “client not allowed to impersonate”.

… and it’s a vanilla setup. I am wondering how those who has to work with production deployment can configure that.