An application proxy option. With Microsoft Entra ID, the recommended default, users must sign in to Entra first so MFA, SSO and Conditional Access take effect; with Passthrough, requests reach the app without Entra authentication and none of those protections apply.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Pre-authentication in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra application proxy
Makes on-premises web applications reachable from outside using a connector that only makes outbound connections, so neither a VPN nor open inbound ports are required.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- FIRST
A DAX function available only inside visual calculations. It fetches the value at the start of one axis of the visual's matrix, which makes it handy for comparing each point with the first; its opposite is LAST.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
- SSO
Signing in once to gain access to multiple applications.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
Related terms
- Kerberos armoring
Wraps Kerberos pre-authentication in an encrypted tunnel; Group Policy must enable support on both clients and domain controllers.
- Protected Users
Members get fixed protections: four-hour TGTs, no delegation, no Digest, CredSSP or NTLM, and no RC4 or DES during Kerberos pre-authentication. Keep computer and service accounts out of this global group.