← Previous day

Day in brief

Kerberos guidance ties Cloud Sync provisioning to passwordless Active Directory access

The period’s substantive updates center on clarifying the end-to-end path from Microsoft Entra ID and Cloud Sync provisioning to Kerberos-protected Active Directory resources. The guidance explains that provisioning alone is insufficient, identifies the required Active Directory accounts and group memberships, and connects Microsoft Entra Kerberos with Windows Hello for Business and FIDO2. A separate Workload ID update distinguishes managed-identity guidance for Chaos Studio Workspaces from the classic service.

  • The Workload ID Kerberos guidance explains that Microsoft Entra users and groups provisioned to Active Directory through Cloud Sync can reach Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. It also explicitly states that provisioning alone does not enable Kerberos or passwordless access.

  • The Microsoft Entra Kerberos introduction now describes how Windows Hello for Business cloud Kerberos trust provides passwordless access to Active Directory resources and points administrators to a deployment guide.

  • The Kerberos guidance states that users accessing Active Directory-protected resources need corresponding Active Directory accounts. Cloud-managed users should be provisioned from Microsoft Entra ID, including the group memberships needed for authorization.

  • The Managed Identities Status table now links Chaos Studio Workspaces to permissions and identity guidance while retaining a separate link for Azure Chaos Studio (classic), helping administrators select documentation for the environment they manage.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

4 updates

2

Introduction to Microsoft Entra Kerberos

New feature

The page now describes how Windows Hello for Business cloud Kerberos trust uses Microsoft Entra Kerberos to provide passwordless access to Active Directory resources and links to a deployment guide.

Kerberos

Doc updateAction required

The documentation now states that users accessing Active Directory-protected resources need corresponding Active Directory accounts. Cloud-managed users should be provisioned from Microsoft Entra ID, including required group memberships.

1

Kerberos

Doc update

The page now explains how Microsoft Entra ID users and groups provisioned to Active Directory with Cloud Sync can access Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. It also clarifies that provisioning alone does not enable Kerberos or passwordless access.

1

Managed Identities Status

Doc update

The managed identities status table now links to permissions and identity guidance for Chaos Studio Workspaces, while retaining a separate link for Azure Chaos Studio (classic).

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…