Entra.Chat

Microsoft's Entra Kerberos: Bridging Legacy AD to Cloud Auth + MAM on Edge with PM Jordan Gross


Listen Later

In this episode we chat with Microsoft PM Jordan Gross about the exciting world of Entra Kerberos.

Discover how this crucial feature bridges the gap between traditional on-premises Active Directory and the modern cloud, enabling seamless authentication for legacy applications in hybrid environments.

Jordan delves into the mechanics of Entra Kerberos, its different operational modes (up-level and down-level trust), and its significance for organizations migrating to the cloud.

We also explore MAM (Mobile Application Management) on Edge, another innovative solution Jordan worked on, which helps secure browser access on personal devices.

LinkedIn - https://www.linkedin.com/in/jordangross61/

PS. Can I ask a favor? If you enjoy this podcast please leave a review and rating on your podcast app! This helps more folks discover Entra.Chat - Thank you πŸ™ - Merill

Watch on YouTube or get the podcast from the links below πŸ‘‡

πŸ”— Related Links

Entra Kerboros

* How Azure AD Kerberos Works β€’ Steve Syfuhs

* Cloud Kerberos trust deployment guide

* Use Kerberos for single sign-on (SSO) to your resources with Microsoft Entra Private Access

* Kerberos Constrained Delegation for single sign-on (SSO) to your apps with application proxy

* Enable Microsoft Entra Kerberos authentication for hybrid identities on Azure Files

* How Windows Authentication for Azure SQL Managed Instance is implemented with Microsoft Entra ID and Kerberos

* Configure single sign-on for Azure Virtual Desktop using Microsoft Entra ID

* Enable Kerberos SSO to on-premises Active Directory and Microsoft Entra ID Kerberos resources in Platform SSO (MacOS)

MAM

* Data protection for Windows MAM

πŸ“— Chapters

00:00 Intro

01:24 Introducing Entra Kerberos & MAM on Edge

03:13 What is Entra Kerberos?

04:14 Understanding Traditional Kerberos

06:39 Why Entra Didn't Just Use Kerberos Initially

07:36 The Lingering Importance of On-Prem AD

09:08 Where Entra Kerberos Fits: Solving Hybrid Problems

10:06 Use Cases: Regulations & File Sharing (SMB Protocol)

11:55 How Entra Kerberos Works: Two Styles

13:36 Modern Auth vs. Down-Level Trust Explained

14:04 The Convenience of Cloud TGTs with Windows Hello

15:26 Accessing Resources: TGT to TGS Exchange

17:03 How Apps Trust Entra Kerberos Tickets

18:00 Admin Setup for Trust Relationship

19:22 Supporting Legacy Apps in a Modern World

21:24 Benefits Over NTLM & Conditional Access

23:04 Future of Entra Kerberos: Cloud-Only Users

26:28 Expanding Support: Mac, Linux & Mobile Devices

29:13 Current Big Use Cases: Azure Files & AVD

30:06 Understanding Down-Level Scenarios

31:42 Interaction with Global Secure Access

33:57 Transition to MAM for Edge

34:27 What Problem Does MAM for Edge Solve?

36:12 How MAM for Edge Protects Personal Devices

38:11 Security Scope: Benign User Mistakes vs. Hackers

40:23 Combining MDM and MAM for Enhanced Security

41:20 Deployment: Intune Policies & Entra Configuration

43:18 Windows-Only Feature for Now

44:10 Benefits: Security, User Empowerment & Visibility

48:13 Intune Dependency & Flexibility with Other MDMs

49:50 The Fun of Cross-Team Collaboration

50:48 Concluding Thoughts & Thank You

Podcast Apps

πŸŽ™οΈ Entra.Chat - https://entra.chat

🎧 Apple Podcast β†’ https://entra.chat/apple

πŸ“Ί YouTube β†’ https://entra.chat/youtube

πŸ“Ί Spotify β†’ https://entra.chat/spotify

🎧 Overcast β†’ https://entra.chat/overcast

🎧 Pocketcast β†’ https://entra.chat/pocketcast

🎧 Others β†’ https://entra.chat/rss

Merill's socials

πŸ“Ί YouTube β†’ youtube.com/@merillx

πŸ‘” LinkedIn β†’ linkedin.com/in/merill

🐀 Twitter β†’ twitter.com/merill

πŸ•Ί TikTok β†’ tiktok.com/@merillf

πŸ¦‹ Bluesky β†’ bsky.app/profile/merill.net

🐘 Mastodon β†’ infosec.exchange/@merill

🧡 Threads β†’ threads.net/@merillf

πŸ€– GitHub β†’ github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
...more
View all episodesView all episodes
Download on the App Store

Entra.ChatBy Merill Fernando

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like Entra.Chat

View all
Risky Business by Patrick Gray

Risky Business

361 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

626 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

366 Listeners

Hacked by Hacked

Hacked

176 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,006 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

312 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,879 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

The Practical 365 Podcast by Practical 365

The Practical 365 Podcast

9 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

24 Listeners

Big Technology Podcast by Alex Kantrowitz

Big Technology Podcast

441 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

127 Listeners

Blue Security by Andy Jaw & Adam Brewer

Blue Security

14 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

43 Listeners