A Microsoft Entra capability, included at no extra cost, that signs people in without a password prompt when they use domain-joined company devices on the company network. It pairs with password hash sync or pass-through authentication; AD FS is not supported.
Also called Seamless SSO.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Seamless single sign-on in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Capability
Something that a person, organisation or system is able to do.
- Password hash sync
Sign-in option in Microsoft Entra Connect that copies password hashes to the cloud, so Microsoft Entra ID itself handles authentication and lockout.
- Pass-through Authentication
Sign-in option in Microsoft Entra Connect where agents running on-premises, using outbound port 443 only, check passwords against AD. No password hashes are kept in the cloud.
- AD FS
Short for Active Directory Federation Services, a federation server hosted on-premises. Its older publishing role, Web Application Proxy, is a separate thing from Microsoft Entra application proxy.
Related terms
- Active Directory - Integrated
Sign-in choice in SSMS, since renamed Microsoft Entra Integrated, that silently passes on a hybrid user's existing Windows credentials using federation or seamless SSO.
- AZUREADSSOACC
Seamless SSO adds this computer account to each synchronised forest. Microsoft Entra ID holds a copy of its Kerberos decryption key, so restrict management to Domain Admins and roll the key over no less often than every 30 days.
- Primary Refresh Token
Microsoft Entra registered and joined devices hold this token, which gives users seamless single sign-on to apps integrated with Entra.