Kerberos looks this name up to find which account a particular service instance runs as. Application proxy uses it when doing Kerberos constrained delegation to an app.
Also called service principal name.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SPN in context, with comparison tables and the common traps.
Terms in this definition
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- Microsoft Entra application proxy
Makes on-premises web applications reachable from outside using a connector that only makes outbound connections, so neither a VPN nor open inbound ports are required.
- Kerberos Constrained Delegation
Mechanism allowing a service, for instance Entra application proxy, to request Kerberos tickets on behalf of a user so that apps using Integrated Windows Authentication get single sign-on.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
Related terms
- Name suffix routing
Decides, on a forest trust, which DNS, SPN and UPN suffixes have their authentication traffic directed across to the other forest.