Microsoft Entra ID
Authentication

Whats New

In brief

The documentation states that generally available key rotation improves reliability for incoming trust referral flows and addresses authentication failures caused when referral tickets used a secondary key.

What Entra admins need to know

Administrators using incoming trust referral flows should review the updated guidance. No required action is stated.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Service category: Authentications (Logins)
Product capability: User Authentication

General availability of Microsoft Entra Kerberos key rotation improved reliability particularly for environments using incoming trust referral flows. Previously, authentication failures could occur during Kerberos key rotation if referral tickets were encrypted with a secondary key. The update enhances validation logic to attempt decryption with both primary and secondary Kerberos keys, improving resiliency during key rollover operations and reducing authentication disruption during rotation events. For more information, see: Rotate the Kerberos server key for Microsoft Entra KerberosRotate the Kerberos server key for Microsoft Entra Kerberos.


Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…