Kerberos clients present one of these when asking for service tickets. Microsoft Entra Kerberos can issue a Cloud version for cloud resources, and also a partial version, containing nothing but the user's SID, which on-premises DCs exchange for a complete ticket.
Also called ticket-granting ticket.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains TGT in context, with comparison tables and the common traps.
Terms in this definition
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
- Microsoft Entra Kerberos
Azure Files identity source where Entra ID hands out the Kerberos tickets for SMB access. It supports hybrid identities and, more recently, cloud-only ones; each storage account can have just one identity source.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- SID
Every Windows or Active Directory user, group and computer gets one, unique and never handed out again. Windows puts it in a person's access token when they log on.
- Deployment modes
The two ways ARM can deploy: Incremental, the default, creates or updates what the template lists and ignores everything else; Complete also removes resource group contents absent from the template.
Related terms
- Cloud Kerberos trust
Microsoft's preferred model for hybrid Windows Hello for Business. Microsoft Entra Kerberos hands out a partial ticket-granting ticket, a domain controller swaps it for a complete one, and there is no need for PKI or synchronising keys.
- TGS
The ticket-granting service: whenever a client shows a valid TGT, this part of the Kerberos KDC on every domain controller hands it a service ticket.