Microsoft Entra ID
Authentication

Configure Microsoft Entra Kerberos trust

In brief

The documentation now covers prerequisites, PowerShell module installation, Trusted Domain Object creation, client ticket configuration, key rotation, and trust removal.

What Entra admins need to know

Administrators have detailed steps and required permissions for configuring and managing Kerberos trust between Microsoft Entra ID and on-premises AD DS.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

new file mode 100644

title: Configure Microsoft Entra Kerberos trust description: Learn how to configure and manage Microsoft Entra Kerberos trust between Microsoft Entra ID and Active Directory Domain Services. manager: pmwongera ms.service: entra-id ms.subservice: authentication ms.topic: how-to ms.date: 10/07/2026 ms.reviewer: Vimala, vimrang, barclayn ms.custom: msecd-doc-authoring-1012 ai-usage: ai-assisted # Customer intent: As an IT admin, I want to configure Microsoft Entra Kerberos trust so that users can access resources by using modern credentials.

Configure Microsoft Entra Kerberos trust

Microsoft Entra Kerberos trust establishes an inbound trust relationship in which on-premises Active Directory Domain Services (AD DS) trusts Microsoft Entra ID as a Kerberos Key Distribution Center (KDC). This trust enables hybrid identity organizations to use modern credentials for applications and allows Microsoft Entra ID to become the trusted source for cloud and on-premises authentication.

This article explains how to create the Trusted Domain Object, configure clients to retrieve Kerberos tickets, rotate the Kerberos key, and remove the trust configuration.

Prerequisites

To complete the steps in this article, you need:

  • A supported Windows client that's joined to Active Directory. The domain must have a functional level of Windows Server 2012 or later.
  • An on-premises Active Directory administrator account that's either a member of the Domain Admins group for the domain or a member of the Enterprise Admins group for the forest.
  • A Microsoft Entra Global Administrator account.
  • Hybrid identities synchronized between on-premises AD DS and Microsoft Entra ID.

Create and configure the Microsoft Entra Kerberos Trusted Domain Object

To create and configure the Microsoft Entra Kerberos Trusted Domain Object, use the Azure AD Hybrid Authentication Management PowerShell module.

Register the Trusted Domain Object with Microsoft Entra ID

Use the Azure AD Hybrid Authentication Management PowerShell module to set up a Trusted Domain Object in the Active Directory domain and register trust information with Microsoft Entra ID. This action creates an inbound trust relationship, which enables on-premises Active Directory to trust Microsoft Entra ID.

You only need to set up the Trusted Domain Object once per domain. If you already set up this object for your domain, skip this section and proceed to Configure clients to retrieve Kerberos tickets.

Install the Azure AD Hybrid Authentication Management PowerShell module

  1. Start a Windows PowerShell session by using the Run as administrator option.

  2. Install the Azure AD Hybrid Authentication Management PowerShell module by using the following script. The script:

    1. Enables TLS 1.2 for communication.
    2. Installs the NuGet package provider.
    3. Registers the PSGallery repository if it isn't already registered.
    4. Configures PSGallery as a trusted repository.
    5. Installs the PowerShellGet module.
    6. Installs the Azure AD Hybrid Authentication Management PowerShell module.

    The Azure AD Hybrid Authentication Management PowerShell module uses the AzureADPreview module, which provides advanced Microsoft Entra management features. To prevent unnecessary installation conflicts with the Azure AD PowerShell module, the installation command includes the -AllowClobber parameter.

    [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
    
    Install-PackageProvider -Name NuGet -Force
    
    if (@(Get-PSRepository | Where-Object { $_.Name -eq "PSGallery" }).Count -eq 0) {
        Register-PSRepository -Default
    }
    
    Set-PSRepository -Name "PSGallery" -InstallationPolicy Trusted
    
    Install-Module -Name PowerShellGet -Force
    
    Install-Module -Name AzureADHybridAuthenticationManagement -AllowClobber
    

Create the Trusted Domain Object

  1. Start a Windows PowerShell session by using the Run as administrator option.

  2. Set the common parameters. Customize the script before you run it.

    1. Set the $domain parameter to your on-premises Active Directory domain name.
    2. When Get-Credential prompts you, enter the credentials for an on-premises Active Directory administrator account. The account must meet the permissions described in Prerequisites.
    3. Set the $cloudUserName parameter to the user principal name of a Microsoft Entra Global Administrator account.
```powershell
$domain = "your on-premises domain name, for example contoso.com"
$domainCred = Get-Credential
$cloudUserName = "Microsoft Entra ID user principal name, for example [email protected]"
```
  1. Check the current Kerberos domain settings:

    Get-AzureADKerberosServer -Domain $domain `
        -DomainCredential $domainCred `
        -UserPrincipalName $cloudUserName
    

    The first time you call a Microsoft Entra Kerberos command, you're prompted for Microsoft Entra ID access. Enter the password for your Microsoft Entra Global Administrator account. If your organization uses another modern authentication method, such as Microsoft Entra multifactor authentication or a smart card, follow the sign-in instructions.

    If Microsoft Entra Kerberos isn't configured, the Get-AzureADKerberosServer cmdlet displays empty information:

    ID                  :
    UserAccount         :
    ComputerAccount     :
    DisplayName         :
    DomainDnsName       :
    KeyVersion          :
    KeyUpdatedOn        :
    KeyUpdatedFrom      :
    CloudDisplayName    :
    CloudDomainDnsName  :
    CloudId             :
    CloudKeyVersion     :
    CloudKeyUpdatedOn   :
    CloudTrustDisplay   :
    

    If your domain already supports FIDO2 security key authentication, the cmdlet displays Microsoft Entra service account information. The CloudTrustDisplay field is empty:

    ID                  : XXXXX
    UserAccount         : CN=krbtgt-AzureAD, CN=Users, DC=contoso, DC=com
    ComputerAccount     : CN=AzureADKerberos, OU=Domain Controllers, DC=contoso, DC=com
    DisplayName         : XXXXXX_XXXXX
    DomainDnsName       : contoso.com
    KeyVersion          : 53325
    KeyUpdatedOn        : 2/24/2024 9:03:15 AM
    KeyUpdatedFrom      : ds-aad-auth-dem.contoso.com
    CloudDisplayName    : XXXXXX_XXXXX
    CloudDomainDnsName  : contoso.com
    CloudId             : XXXXX
    CloudKeyVersion     : 53325
    CloudKeyUpdatedOn   : 2/24/2024 9:03:15 AM
    CloudTrustDisplay   :
    
  2. Add the Trusted Domain Object.

    Run the Set-AzureADKerberosServer cmdlet with the -SetupCloudTrust parameter. If a Microsoft Entra service account doesn't exist, this command creates one. The command creates the Trusted Domain Object only when a Microsoft Entra service account is available.

    Set-AzureADKerberosServer -Domain $domain `
        -UserPrincipalName $cloudUserName `
        -DomainCredential $domainCred `
        -SetupCloudTrust
    
After you create the Trusted Domain Object, check the updated Kerberos settings by using the `Get-AzureADKerberosServer` cmdlet. When the `Set-AzureADKerberosServer` cmdlet completes successfully with the `-SetupCloudTrust` parameter, the `CloudTrustDisplay` field returns `Microsoft.AzureAD.Kdc.Service.TrustDisplay`:

```output
ID                  : XXXXX
UserAccount         : CN=krbtgt-AzureAD, CN=Users, DC=contoso, DC=com
ComputerAccount     : CN=AzureADKerberos, OU=Domain Controllers, DC=contoso, DC=com
DisplayName         : XXXXXX_XXXXX
DomainDnsName       : contoso.com
KeyVersion          : 53325
KeyUpdatedOn        : 2/24/2024 9:03:15 AM
KeyUpdatedFrom      : ds-aad-auth-dem.contoso.com
CloudDisplayName    : XXXXXX_XXXXX
CloudDomainDnsName  : contoso.com
CloudId             : XXXXX
CloudKeyVersion     : 53325
CloudKeyUpdatedOn   : 2/24/2024 9:03:15 AM
CloudTrustDisplay   : Microsoft.AzureAD.Kdc.Service.TrustDisplay
```

Configure clients to retrieve Kerberos tickets

Identify your Microsoft Entra tenant ID, and use Group Policy to configure every client that needs to retrieve Microsoft Entra Kerberos tickets.

Set Administrative Templates\System\Kerberos\Specify KDC proxy servers for Kerberos clients to Enabled:

  1. Edit the Administrative Templates\System\Kerberos\Specify KDC proxy servers for Kerberos clients policy setting.

  2. Select Enabled.

  3. Under Options, select Show....

  4. Define the KDC proxy server mapping shown in the following table. Replace your_Microsoft_Entra_tenant_ID with your tenant ID. Include the space after https and before the closing / in the value.

    Value nameValue
    KERBEROS.MICROSOFTONLINE.COM<https login.microsoftonline.com:443:your_Microsoft_Entra_tenant_ID/kerberos />
  5. Select OK to close the Show Contents dialog.

  6. Select Apply in the Specify KDC proxy servers for Kerberos clients dialog.

Rotate the Kerberos key

Microsoft Entra Kerberos uses a shared Kerberos server key between on-premises AD DS and Microsoft Entra ID. The key encrypts and protects Ticket Granting Tickets (TGTs) issued by Microsoft Entra ID. It's stored on a dedicated Microsoft Entra Kerberos server object in on-premises Active Directory and securely published to Microsoft Entra ID. This object is logical, not a physical server, and functions like a read-only domain controller (RODC) for Kerberos trust.

Rotate the key periodically for the Microsoft Entra service account and Trusted Domain Object. Regular rotation:

  • Limits the lifetime of cryptographic material.
  • Reduces risk if a key is compromised.
  • Aligns with standard Kerberos and Active Directory security practices.

Microsoft doesn't mandate a fixed rotation interval. Rotate the Microsoft Entra Kerberos server key on the same schedule as other Active Directory Kerberos (krbtgt) keys, during scheduled security maintenance windows, and immediately after a suspected credential compromise.

How key rotation works

Microsoft Entra Kerberos uses a dual-key model to avoid service disruption during rotation:

  • Primary key: Encrypts all newly issued Kerberos tickets.
  • Secondary key: Retains the previous key to validate existing tickets until they expire.

When you rotate the key, the new key becomes the primary key, and the previous primary key becomes the secondary key. Microsoft Entra ID uses the primary key for new Kerberos tickets and continues to honor tickets protected by the secondary key. This process doesn't interrupt user access.

Rotate the key

Use the Set-AzureADKerberosServer cmdlet to rotate the key. The command:

  • Generates a new Kerberos server key.
  • Stores the key on the on-premises Active Directory Kerberos server object.
  • Securely publishes the key to Microsoft Entra ID.
  • Updates the key version in both environments.
Set-AzureADKerberosServer -Domain $domain `
    -DomainCredential $domainCred `
    -UserPrincipalName $cloudUserName `
    -SetupCloudTrust `
    -RotateServerKey

After you rotate the key, allow several hours for the changed key to propagate between the Kerberos KDC servers. Because of this key distribution timing, you can rotate the key once within 24 hours.

Use the -Force parameter

If you need to rotate the key again within 24 hours, such as immediately after creating the Trusted Domain Object, add the -Force parameter:

Set-AzureADKerberosServer -Domain $domain `
    -DomainCredential $domainCred `
    -UserPrincipalName $cloudUserName `
    -SetupCloudTrust `
    -RotateServerKey `
    -Force

The -Force parameter applies or updates the Kerberos server configuration without confirmation prompts while maintaining security controls. Use it when:

  • You need to rotate the key again within 24 hours.
  • You rerun the command to repair or reconcile configuration.
  • You automate Kerberos setup or key management.
  • You recover from a partial or failed configuration attempt.
  • You need to ensure consistent state across environments without manual confirmation.

Remove the Trusted Domain Object

Remove the Trusted Domain Object:

Remove-AzureADKerberosServerTrustedDomainObject -Domain $domain `
    -DomainCredential $domainCred `
    -UserPrincipalName $cloudUserName

This command removes only the Trusted Domain Object. If your domain supports FIDO2 security key authentication, you can remove the object while maintaining the Microsoft Entra service account required for that authentication service.

Remove all Kerberos settings

Remove both the Microsoft Entra service account and the Trusted Domain Object:

Remove-AzureADKerberosServer -Domain $domain `
    -DomainCredential $domainCred `
    -UserPrincipalName $cloudUserName

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…