Configure Microsoft Entra Kerberos trust
Doc updateThe documentation now covers prerequisites, PowerShell module installation, Trusted Domain Object creation, client ticket configuration, key rotation, and trust removal.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Microsoft added a full configuration path for Microsoft Entra Kerberos trust, from prerequisites and PowerShell installation through trust removal, while deleting the standalone server-key-rotation article. A separate update identifies key rotation as generally available for incoming trust referral flows and records a June 15, 2026 baseline-scope enforcement rollout, with a Graph query for affected Conditional Access policies.
The new article documents prerequisites, required permissions, PowerShell module installation, Trusted Domain Object creation, client ticket configuration, key rotation, and trust removal for Kerberos trust between Microsoft Entra ID and on-premises AD DS.
The updated What's New entry says generally available key rotation improves reliability for incoming trust referral flows and addresses authentication failures that occurred when referral tickets used a secondary key. No required administrator action is stated.
Microsoft deleted the article covering Kerberos server-key-rotation prerequisites, dual-key behavior, and the Set-AzureADKerberosServer procedure. Administrators seeking that material must locate the instructions elsewhere in the documentation.
The Conditional Access page now states that baseline-scope enforcement rollout began June 15, 2026, adds a Microsoft Graph query for affected policies, and clarifies customization and sign-in review guidance.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The documentation now covers prerequisites, PowerShell module installation, Trusted Domain Object creation, client ticket configuration, key rotation, and trust removal.
The documentation states that generally available key rotation improves reliability for incoming trust referral flows and addresses authentication failures caused when referral tickets used a secondary key.
The standalone article describing Kerberos server-key rotation, prerequisites, dual-key behavior, and the Set-AzureADKerberosServer procedure was deleted.
The documentation now states that baseline-scope enforcement rollout began June 15, 2026. It adds a Microsoft Graph query for finding affected Conditional Access policies and clarifies customization and sign-in review guidance.