๐ Secure Bits ๐ก
๐ฌ๐ผ๐ ๐บ๐ถ๐ด๐ต๐ ๐๐ฎ๐ป๐ ๐๐ผ ๐๐๐ฟ๐ป ๐ผ๐ณ๐ณ ๐๐ป๐๐ฟ๐ฎ ๐๐ผ๐ป๐ป๐ฒ๐ฐ๐ ๐ฆ๐ฒ๐ฎ๐บ๐น๐ฒ๐๐ ๐ฆ๐ฆ๐ข. ๐๐ฒ๐ฟ๐ฒ’๐ ๐๐ต๐.
In many hybrid Microsoft 365 tenants, Seamless SSO is still enabled โ even though itโs no longer needed in modern Entra ID environments.
Nothing looks broken. Users sign in just fine.
And thatโs exactly why this often goes unnoticed.
๐ค ๐ช๐ต๐ ๐ฏ๐ผ๐๐ต๐ฒ๐ฟ?
Seamless SSO introduces an ๐ฎ๐ฑ๐ฑ๐ถ๐๐ถ๐ผ๐ป๐ฎ๐น ๐ฎ๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐บ๐ฒ๐ฐ๐ต๐ฎ๐ป๐ถ๐๐บ that most environments donโt actually need anymore.
Modern Windows 10/11 devices already rely on ๐ฃ๐ฟ๐ถ๐บ๐ฎ๐ฟ๐ ๐ฅ๐ฒ๐ณ๐ฟ๐ฒ๐๐ต ๐ง๐ผ๐ธ๐ฒ๐ป๐ (๐ฃ๐ฅ๐ง) for seamless access. Keeping Seamless SSO expands attack surface unnecessarily โ without delivering any value.
Seamless SSO relies on Kerberos-based authentication. It uses a special on-prem AD computer account: ๐๐ญ๐จ๐ฅ๐๐๐๐ฆ๐ฆ๐ข๐๐๐. That account holds a ๐๐ต๐ฎ๐ฟ๐ฒ๐ฑ ๐๐ฒ๐ฐ๐ฟ๐ฒ๐ between on-prem AD and Entra ID. If the secret gets compromised, it weakens your identity trust boundary.
๐ ๏ธ ๐๐๐ฎ๐น๐๐ฎ๐๐ฒ ๐ถ๐ณ ๐๐ผ๐ ๐๐๐ถ๐น๐น ๐ป๐ฒ๐ฒ๐ฑ ๐ฆ๐ฒ๐ฎ๐บ๐น๐ฒ๐๐ ๐ฆ๐ฆ๐ข
– Do you have Hybrid Entra Join + Windows 10/11?
– Are you trying to use Modern authentication wherever you can?
– No legacy domain-joined-only scenarios?
If the answer to above questions is yes, Seamless SSO is likely not needed.
๐ก๏ธ ๐๐ถ๐๐ฎ๐ฏ๐น๐ฒ ๐ฆ๐ฒ๐ฎ๐บ๐น๐ฒ๐๐ ๐ฆ๐ฆ๐ข ๐ถ๐ป ๐๐ป๐๐ฟ๐ฎ ๐๐ผ๐ป๐ป๐ฒ๐ฐ๐ ๐ฆ๐๐ป๐ฐ
– Edit Microsoft Entra Connect configuration in the ๐๐ฉ๐ข๐ฏ๐จ๐ฆ ๐ถ๐ด๐ฆ๐ณ ๐ด๐ช๐จ๐ฏ-๐ช๐ฏ section
– Uncheck ๐๐ฏ๐ข๐ฃ๐ญ๐ฆ ๐ด๐ช๐ฏ๐จ๐ญ๐ฆ ๐ด๐ช๐จ๐ฏ-๐ฐ๐ฏ
– Monitor sign-in behavior
– Validate PRT-based authentication continues to work
– Delete the AZUREADSSOACC afterwards
โ ๏ธ ๐๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐
– First, check whether Seamless SSO is active using ๐๐ถ๐ฅ๐ช๐ต ๐๐ฆ๐ณ๐ฃ๐ฆ๐ณ๐ฐ๐ด ๐๐ฆ๐ณ๐ท๐ช๐ค๐ฆ ๐๐ช๐ค๐ฌ๐ฆ๐ต ๐๐ฑ๐ฆ๐ณ๐ข๐ต๐ช๐ฐ๐ฏ๐ด GPO and logs
– Communicate with users before changing auth flows
โ If youโre aiming for Zero Trust and cloud-native identity, ๐๐๐ฎ๐ฟ๐ ๐ฟ๐ฒ๐บ๐ผ๐๐ถ๐ป๐ด ๐ฎ๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐ฝ๐ฎ๐๐ต๐ you no longer need. If a feature exists only โbecause it always didโ, itโs time to question it.
๐ฌ Have you already disabled Seamless SSO or is it still running quietly in your environment?
๐๐ถ๐ต๐ฉ๐ฐ๐ณ ๐ฐ๐ง ๐ต๐ฉ๐ฆ ๐ฑ๐ฐ๐ด๐ต:
Martin Strnad
