Microsoft Entra Workload ID
Authentication

Kerberos

In brief

The page now explains how Microsoft Entra ID users and groups provisioned to Active Directory with Cloud Sync can access Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. It also clarifies that provisioning alone does not enable Kerberos or passwordless access.

What Entra admins need to know

Admins planning a cloud-first identity model can use the guidance to understand the required provisioning and authentication flow.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Scenarios

Microsoft Entra Kerberos serves as a foundation for several authentication scenarios that provide access to Active Directory resources by using modern authentication methods. These scenarios include access for cloud-managed identities, Windows Hello for Business cloud Kerberos trust, FIDO2 security key sign-in, Azure Files authentication, Azure Virtual Desktop profile access, and Platform SSO on macOS.

Windows Hello for Business cloud Kerberos trust

For more information, see the Windows Hello for Business cloud Kerberos trust deployment guide.

Access Active Directory resources with cloud-managed identities

Organizations adopting a cloud-first identity model can manage users and groups in Microsoft Entra ID while continuing to use applications and resources protected by Active Directory.

By using Microsoft Entra Cloud Sync, organizations can provision Microsoft Entra ID users, groups, and memberships to Active Directory. Microsoft Entra Kerberos enables those users to access Kerberos-protected resources by using modern authentication methods such as Windows Hello for Business cloud Kerberos trust and FIDO2 security keys.

This scenario enables organizations to:

  • Move user and group source of authority to Microsoft Entra ID.
  • Reduce dependency on on-premises identity management.
  • Continue accessing Kerberos-protected applications and resources.
  • Support cloud-managed identities while maintaining compatibility with existing Active Directory environments.

The following example illustrates how cloud-managed identities that are provisioned to Active Directory can use Microsoft Entra Kerberos:

  1. A user account is managed in Microsoft Entra ID.
  2. Microsoft Entra Cloud Sync provisions the user to Active Directory.
  3. The user signs in by using Windows Hello for Business or a FIDO2 security key.
  4. Microsoft Entra ID issues a Microsoft Entra Kerberos ticket.
  5. Active Directory issues Kerberos service tickets for authorized resources.
  6. The user accesses Kerberos-protected applications and resources without entering a password.

Examples of supported resources include:

  • Windows file shares.
  • Internet Information Services (IIS) applications that use Windows Integrated Authentication.
  • Azure Files.
  • Line-of-business applications that rely on Kerberos authentication.

For more information, see:

Use Microsoft Entra Kerberos for Windows authentication access to Azure SQL Managed Instance

Kerberos authentication for Microsoft Entra ID enables Windows authentication access to Azure SQL Managed Instance. Windows authentication for managed instances empowers customers to move existing services to the cloud while maintaining a seamless user experience. This ability provides the basis for infrastructure modernization.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…