Terme informatique

Seamless Single Sign-On

A Microsoft Entra hybrid identity feature that lets users on the corporate network sign in automatically to supported services without re-entering their password.

⌚ About 2 min read
View my favorites

Seamless Single Sign-On is a Microsoft Entra hybrid identity feature that lets users on the corporate network sign in automatically to supported services without re-entering their password.

Simple definition

Seamless Single Sign-On is a Microsoft Entra hybrid identity feature that lets users on the corporate network sign in automatically to supported services without re-entering their password. It belongs to the Microsoft 365 / Entra / Intune vocabulary and is useful when reading architecture diagrams, product documentation, logs, or administration procedures.

What is it used for?

Its main purpose is to improve the SSO experience for domain-joined devices in selected hybrid-authentication scenarios. The practical value depends on the surrounding architecture, security model, and operational requirements.

How does it work?

The browser can use Kerberos against a configured object/endpoint to prove the user's identity to the Entra flow, avoiding another password prompt.

Key points

  • Scope: A Microsoft Entra hybrid identity feature that lets users on the corporate network sign in automatically to supported services without re-entering their password.
  • Operational goal: Improve the SSO experience for domain-joined devices in selected hybrid-authentication scenarios.
  • Implementation: The browser can use Kerberos against a configured object/endpoint to prove the user's identity to the Entra flow, avoiding another password prompt.

Points to watch

Behavior depends on browser, intranet-zone, DNS, and hybrid configuration; do not confuse it with MFA.

In short

Seamless Single Sign-On = a Microsoft Entra hybrid identity feature that lets users on the corporate network sign in automatically to supported services without re-entering their password. Use it when you need to improve the SSO experience for domain-joined devices in selected hybrid-authentication scenarios.

♡ 0