Entra feature that silently signs in domain-joined devices on the corporate network when using pass-through authentication or password hash sync, though not AD FS. No inbound ports are needed, but autologon.microsoftazuread-sso.com must be in the Local intranet zone.
Also called Microsoft Entra seamless single sign-on.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Seamless SSO in context, with comparison tables and the common traps.
Terms in this definition
- Pass-through Authentication
Sign-in option in Microsoft Entra Connect where agents running on-premises, using outbound port 443 only, check passwords against AD. No password hashes are kept in the cloud.
- Password hash sync
Sign-in option in Microsoft Entra Connect that copies password hashes to the cloud, so Microsoft Entra ID itself handles authentication and lockout.
- AD FS
Short for Active Directory Federation Services, a federation server hosted on-premises. Its older publishing role, Web Application Proxy, is a separate thing from Microsoft Entra application proxy.
- LSDOU
The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.