• leehbi - Friday, February 9, 2018 7:38 AM

    We're running SSRS, no IIS.  I read that disabling loopback will prevent users from having to enter domain credentials multiple times when executing a report.
    I wondered if this KB is still relevant SSRS 2016 with no IIS.  Also, isn't loopback a security feature?

    I don't think that's much of an issue anymore but it doesn't sound like it would apply anyway. Maybe it does but if this is happening when running reports, check the data source settings for the report or report. That is more often the issue when it is when running the reports. If they are prompted multiple times and the report never displays or you get a blank screen then it's usually Kerberos. You may also find more information in the Reporting Services log file.
    Yes it was oiginally implemented for NTLM reflection attacks.

    Sue