Lets people authenticate to Microsoft Entra by presenting an X.509 certificate from your organisation's PKI. Scoped to a group, it becomes an extra option, can count as passwordless MFA and doesn't stop anyone using other methods.
Also called CBA.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Certificate-based authentication in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- PKI
Public key infrastructure, the certificate authorities and procedures that issue certificates. Certificate-based authentication cannot work without it.
- COUNT
A DAX function returning how many non-blank numbers, dates or text values a column contains. Boolean columns need COUNTA instead, and for counting the rows of a table COUNTROWS is the better choice.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
- Stop sequence
One of up to four strings that make the model halt generation; the sequence itself is not included in the output.
Related terms
- Authentication binding policy
Rules in this certificate-based authentication setting, matched on certificate issuer or policy OID, can lift a certificate from the tenant default (single-factor, low affinity) to multifactor or to high affinity binding.
- Authentication methods policy
Tenant-level Microsoft Entra policy that switches on each sign-in method, such as FIDO2, Authenticator, certificate-based authentication, TAP or SMS, for chosen users or groups.
- CRL
Certificate revocation list: a CA publishes the certificates it has withdrawn at a CRL distribution point. Certificate-based authentication downloads that list and rejects any revoked user certificate; if there is no CRL, no revocation check happens unless validation is set as required.
- OCSP
The Online Certificate Status Protocol for checking whether a certificate has been revoked. Microsoft Entra certificate-based authentication does not use it, relying instead on a single CRL distribution point for each CA.
- OID
An object identifier naming a certificate policy. Certificate-based authentication can match on it with rules that beat issuer rules, for example to count a certificate as multifactor or to insist on high-affinity binding.
- Phishing-resistant MFA
Authentication that is tied to the real website and the user's device, so a fake site cannot capture and replay it. Examples include passkeys (FIDO2), Windows Hello for Business and certificate-based authentication used as multifactor; Conditional Access can demand these through a built-in authentication strength.
- PKI-based trust store
The recommended trust store for certificate-based authentication, holding each PKI's CAs in its own container (a maximum of 250 CAs at 8 KB apiece) and supporting issuer hints. Privileged Authentication Administrators manage it, and uploading a PKI in bulk needs P1 or P2.
- Username binding policy
Decides how certificate-based authentication locates the account, by matching a chosen certificate field with a chosen user attribute. Out of the box, Principal Name is checked against userPrincipalName.