Sign-in method where domain users access apps with their existing Windows credentials over Kerberos or NTLM. To expose such apps outside the network, Microsoft Entra application proxy can publish them using Kerberos Constrained Delegation.
Also called Integrated Windows Authentication.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains IWA in context, with comparison tables and the common traps.
Terms in this definition
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
- NTLM
NT LAN Manager, an older Windows challenge-response protocol available through Microsoft Entra Domain Services. Mounting Azure Files over SMB with a key relies on NTLMv2, so permitting Kerberos alone breaks such mounts.
- Microsoft Entra application proxy
Makes on-premises web applications reachable from outside using a connector that only makes outbound connections, so neither a VPN nor open inbound ports are required.
- Kerberos Constrained Delegation
Mechanism allowing a service, for instance Entra application proxy, to request Kerberos tickets on behalf of a user so that apps using Integrated Windows Authentication get single sign-on.