Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500SC-300AZ-802
Each book explains Kerberos in context, with comparison tables and the common traps.
Terms in this definition
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
- AD
Short for Active Directory, the directory service built into Windows Server (AD DS). Entra Connect synchronises on-premises forests to Microsoft Entra ID.
- Azure Files
Azure's managed file shares over SMB or NFS. There is no Archive tier, and a single encryption key applies across the whole storage account.
- Microsoft Entra Domain Services
Domain hosted and managed in Azure that provides Kerberos, NTLM and LDAP. Its contents come from Entra ID, so no connection to on-premises is required.
- Microsoft Entra application proxy
Makes on-premises web applications reachable from outside using a connector that only makes outbound connections, so neither a VPN nor open inbound ports are required.
- Kerberos Constrained Delegation
Mechanism allowing a service, for instance Entra application proxy, to request Kerberos tickets on behalf of a user so that apps using Integrated Windows Authentication get single sign-on.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
Related terms
- AD DS authentication (Azure Files)
Option that domain-joins a storage account to on-premises AD DS, letting synced hybrid users mount its SMB shares using Kerberos. RBAC controls share-level access, while Windows ACLs govern files and folders.
- Authentication policy
Lets administrators control how long Kerberos ticket-granting tickets last for chosen accounts and under what conditions they may access things. Introduced as an AD DS object at the Windows Server 2012 R2 domain functional level.
- AZUREADSSOACC
Seamless SSO adds this computer account to each synchronised forest. Microsoft Entra ID holds a copy of its Kerberos decryption key, so restrict management to Domain Admins and roll the key over no less often than every 30 days.
- Credential Guard
Uses virtualisation-based security to isolate Kerberos TGTs and NTLM hashes. Windows Server 2025 enables it automatically on domain-joined member servers (not DCs), which breaks live migration relying on CredSSP.
- DefaultDomainSupportedEncTypes
Registry setting on the KDC that defines which Kerberos encryption types apply to accounts without msDS-SupportedEncryptionTypes; 0x18 limits them to AES256 and AES128.
- Delegated Login Identity
When single sign-on uses Kerberos Constrained Delegation through application proxy and a user's cloud name doesn't match their on-premises name, this option picks the identity the connector requests a Kerberos ticket for. Choices include the UPN and the on-premises SAM account name.
- DES
An outdated encryption type for Kerberos that current versions of Windows disable by default. With Credential Guard turned on, Kerberos cannot use DES at all.
- Identity-based authentication
SMB access to Azure Files using identities from AD DS, Entra Domain Services or Entra Kerberos. SAS tokens play no part in SMB access.