Sign-in option in Microsoft Entra Connect where agents running on-premises, using outbound port 443 only, check passwords against AD. No password hashes are kept in the cloud.
Also called PTA.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Pass-through Authentication in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra Connect
Keeps Microsoft Entra ID in step with an on-premises Active Directory by synchronising its identities to the cloud.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
Related terms
- Hybrid Identity Administrator
The Entra role for managing federation, PHS, PTA, cloud sync and Entra Connect settings. It is the cloud role with the least privilege that still covers Entra Connect.
- Seamless single sign-on
A Microsoft Entra capability, included at no extra cost, that signs people in without a password prompt when they use domain-joined company devices on the company network. It pairs with password hash sync or pass-through authentication; AD FS is not supported.
- Seamless SSO
Entra feature that silently signs in domain-joined devices on the corporate network when using pass-through authentication or password hash sync, though not AD FS. No inbound ports are needed, but autologon.microsoftazuread-sso.com must be in the Local intranet zone.