Microsoft's preferred model for hybrid Windows Hello for Business. Microsoft Entra Kerberos hands out a partial ticket-granting ticket, a domain controller swaps it for a complete one, and there is no need for PKI or synchronising keys.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Cloud Kerberos trust in context, with comparison tables and the common traps.
Terms in this definition
- Windows Hello for Business
Sign-in for Windows that needs no password and resists phishing, provided the device has suitable hardware.
- Microsoft Entra Kerberos
Azure Files identity source where Entra ID hands out the Kerberos tickets for SMB access. It supports hybrid identities and, more recently, cloud-only ones; each storage account can have just one identity source.
- TGT
Kerberos clients present one of these when asking for service tickets. Microsoft Entra Kerberos can issue a Cloud version for cloud resources, and also a partial version, containing nothing but the user's SID, which on-premises DCs exchange for a complete ticket.
- DC
A server running AD DS. Placing these servers in Azure as well as on-premises keeps synchronisation and user sign-in working if one location fails.
- Deployment modes
The two ways ARM can deploy: Incremental, the default, creates or updates what the template lists and ignores everything else; Complete also removes resource group contents absent from the template.
- PKI
Public key infrastructure, the certificate authorities and procedures that issue certificates. Certificate-based authentication cannot work without it.
Related terms
- Certificate trust
With this Windows Hello for Business model, AD FS acts as registration authority while an enterprise PKI hands users their sign-in certificates. Its hybrid form depends on AD FS federation, and cloud Kerberos trust is now Microsoft's preferred choice.
- Key trust
A Windows Hello for Business deployment model where a key bound to the device signs users in to Active Directory through certificate-based Kerberos, which means domain controllers must hold certificates. Microsoft now prefers cloud Kerberos trust.