Microsoft Entra ID
Authentication

Kerberos

In brief

The documentation now states that users accessing Active Directory-protected resources need corresponding Active Directory accounts. Cloud-managed users should be provisioned from Microsoft Entra ID, including required group memberships.

What Entra admins need to know

Ensure applicable cloud-managed users are provisioned in Active Directory so domain controllers can authorize access.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Windows Hello for Business cloud Kerberos trust uses Microsoft Entra Kerberos to provide passwordless access to Active Directory resources. After a user signs in with Windows Hello for Business, Microsoft Entra ID issues a cloud-based Kerberos ticket that enables the user to obtain Kerberos service tickets for resources protected by Active Directory, such as file shares and line-of-business applications. This deployment model simplifies passwordless adoption by removing the requirement for certificate deployment or public key infrastructure (PKI).

For more information, see the Windows Hello for Business cloud Kerberos trust deployment guide.

Access Active Directory resources with cloud-managed identities

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…