Kerberos
In brief
The page now explains how Microsoft Entra ID users and groups provisioned to Active Directory with Cloud Sync can access Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. It also clarifies that provisioning alone does not enable Kerberos or passwordless access.
What Entra admins need to know
Admins planning a cloud-first identity model can use the guidance to understand the required provisioning and authentication flow.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Scenarios
Microsoft Entra Kerberos serves as a foundation for several authentication scenarios that provide access to Active Directory resources by using modern authentication methods. These scenarios include access for cloud-managed identities, Windows Hello for Business cloud Kerberos trust, FIDO2 security key sign-in, Azure Files authentication, Azure Virtual Desktop profile access, and Platform SSO on macOS.
Windows Hello for Business cloud Kerberos trust
For more information, see the Windows Hello for Business cloud Kerberos trust deployment guide.
Access Active Directory resources with cloud-managed identities
Organizations adopting a cloud-first identity model can manage users and groups in Microsoft Entra ID while continuing to use applications and resources protected by Active Directory.
By using Microsoft Entra Cloud Sync, organizations can provision Microsoft Entra ID users, groups, and memberships to Active Directory. Microsoft Entra Kerberos enables those users to access Kerberos-protected resources by using modern authentication methods such as Windows Hello for Business cloud Kerberos trust and FIDO2 security keys.
This scenario enables organizations to:
- Move user and group source of authority to Microsoft Entra ID.
- Reduce dependency on on-premises identity management.
- Continue accessing Kerberos-protected applications and resources.
- Support cloud-managed identities while maintaining compatibility with existing Active Directory environments.
The following example illustrates how cloud-managed identities that are provisioned to Active Directory can use Microsoft Entra Kerberos:
- A user account is managed in Microsoft Entra ID.
- Microsoft Entra Cloud Sync provisions the user to Active Directory.
- The user signs in by using Windows Hello for Business or a FIDO2 security key.
- Microsoft Entra ID issues a Microsoft Entra Kerberos ticket.
- Active Directory issues Kerberos service tickets for authorized resources.
- The user accesses Kerberos-protected applications and resources without entering a password.
Examples of supported resources include:
- Windows file shares.
- Internet Information Services (IIS) applications that use Windows Integrated Authentication.
- Azure Files.
- Line-of-business applications that rely on Kerberos authentication.
For more information, see:
Use Microsoft Entra Kerberos for Windows authentication access to Azure SQL Managed Instance
Kerberos authentication for Microsoft Entra ID enables Windows authentication access to Azure SQL Managed Instance. Windows authentication for managed instances empowers customers to move existing services to the cloud while maintaining a seamless user experience. This ability provides the basis for infrastructure modernization.
Related content
- Microsoft Entra cloud-first identity guidance
- Transfer user source of authority to Microsoft Entra ID
- Provision Microsoft Entra ID objects to Active Directory
- Passwordless access to Active Directory resources
- Create the trusted domain object
- Configure clients to retrieve Kerberos tickets
- Configure the Group Policy Object (GPO) for Azure SQL Managed Instance
@@ -197,7 +197,7 @@ For client access to cloud resources: ## Scenarios -Microsoft Entra Kerberos serves as a foundation for several authentication scenarios that provide access to Active Directory resources by using modern authentication methods. These scenarios include Windows Hello for Business cloud Kerberos trust, FIDO2 security key sign-in, Azure Files authentication, Azure Virtual Desktop profile access, and Platform SSO on macOS.+Microsoft Entra Kerberos serves as a foundation for several authentication scenarios that provide access to Active Directory resources by using modern authentication methods. These scenarios include access for cloud-managed identities, Windows Hello for Business cloud Kerberos trust, FIDO2 security key sign-in, Azure Files authentication, Azure Virtual Desktop profile access, and Platform SSO on macOS. ### Windows Hello for Business cloud Kerberos trust @@ -205,6 +205,47 @@ Windows Hello for Business cloud Kerberos trust uses Microsoft Entra Kerberos to For more information, see the [Windows Hello for Business cloud Kerberos trust deployment guide](/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust?tabs=intune). +### Access Active Directory resources with cloud-managed identities++Organizations adopting a cloud-first identity model can manage users and groups in Microsoft Entra ID while continuing to use applications and resources protected by Active Directory.++By using Microsoft Entra Cloud Sync, organizations can provision Microsoft Entra ID users, groups, and memberships to Active Directory. Microsoft Entra Kerberos enables those users to access Kerberos-protected resources by using modern authentication methods such as Windows Hello for Business cloud Kerberos trust and FIDO2 security keys.++This scenario enables organizations to:++- Move user and group source of authority to Microsoft Entra ID.+- Reduce dependency on on-premises identity management.+- Continue accessing Kerberos-protected applications and resources.+- Support cloud-managed identities while maintaining compatibility with existing Active Directory environments.++> [!IMPORTANT]+> Provisioning users from Microsoft Entra ID to Active Directory creates and manages the corresponding Active Directory accounts. Provisioning alone doesn't enable Kerberos authentication or passwordless access to Active Directory resources. To access Kerberos-protected resources by using modern authentication methods, you must also deploy Microsoft Entra Kerberos and configure a supported authentication method, such as Windows Hello for Business cloud Kerberos trust or FIDO2 security keys.++The following example illustrates how cloud-managed identities that are provisioned to Active Directory can use Microsoft Entra Kerberos:++1. A user account is managed in Microsoft Entra ID.+1. Microsoft Entra Cloud Sync provisions the user to Active Directory.+1. The user signs in by using Windows Hello for Business or a FIDO2 security key.+1. Microsoft Entra ID issues a Microsoft Entra Kerberos ticket.+1. Active Directory issues Kerberos service tickets for authorized resources.+1. The user accesses Kerberos-protected applications and resources without entering a password.++Examples of supported resources include:++- Windows file shares.+- Internet Information Services (IIS) applications that use Windows Integrated Authentication.+- Azure Files.+- Line-of-business applications that rely on Kerberos authentication.++> [!NOTE]+> Microsoft Entra Kerberos provides the Kerberos authentication bridge between modern Microsoft Entra authentication methods and traditional Active Directory resources. User provisioning and source-of-authority transfer scenarios can use Microsoft Entra Kerberos to enable continued access to Kerberos-protected resources while adopting a cloud-first identity model.++For more information, see:++- [Provision Microsoft Entra ID objects to Active Directory](~/identity/hybrid/cloud-sync/overview-provision-entra-id-to-active-directory.md).+- [Microsoft Entra cloud-first identity guidance](~/identity/hybrid/guidance-it-architects-source-of-authority.md).+- [Transfer user source of authority to Microsoft Entra ID](~/identity/hybrid/user-source-of-authority-overview.md).+ ### Use Microsoft Entra Kerberos for Windows authentication access to Azure SQL Managed Instance Kerberos authentication for Microsoft Entra ID enables Windows authentication access to Azure SQL Managed Instance. Windows authentication for managed instances empowers customers to move existing services to the cloud while maintaining a seamless user experience. This ability provides the basis for infrastructure modernization.@@ -364,6 +405,10 @@ Content-Type: application/json ## Related content +- [Microsoft Entra cloud-first identity guidance](~/identity/hybrid/guidance-it-architects-source-of-authority.md)+- [Transfer user source of authority to Microsoft Entra ID](~/identity/hybrid/user-source-of-authority-overview.md)+- [Provision Microsoft Entra ID objects to Active Directory](~/identity/hybrid/cloud-sync/overview-provision-entra-id-to-active-directory.md)+- [Passwordless access to Active Directory resources](/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust) - [Create the trusted domain object](/azure/storage/files/storage-files-identity-auth-hybrid-cloud-trust?tabs=azure-portal&preserve-view=true#create-the-trusted-domain-object) - [Configure clients to retrieve Kerberos tickets](/azure/storage/files/storage-files-identity-auth-hybrid-identities-enable?tabs=azure-portal%2Cintune&preserve-view=true#configure-the-clients-to-retrieve-kerberos-tickets) - [Configure the Group Policy Object (GPO) for Azure SQL Managed Instance](/azure/azure-sql/managed-instance/winauth-azuread-setup-incoming-trust-based-flow?view=azuresql&preserve-view=true#configure-the-group-policy-object-gpo) 