Kerberos Authentication
Kerberos Authentication
Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016
Feature description
The Windows Server operating systems implement the Kerberos version 5
authentication protocol and extensions for public key authentication, transporting
authorization data, and delegation. The Kerberos authentication client is
implemented as a security support provider (SSP), and it can be accessed through the
Security Support Provider Interface (SSPI). Initial user authentication is integrated
with the Winlogon single sign-on architecture.
The Kerberos Key Distribution Center (KDC) is integrated with other Windows Server
security services that run on the domain controller. The KDC uses the domain's Active
Directory Domain Services database as its security account database. Active Directory
Domain Services is required for default Kerberos implementations within the domain
or forest.
Practical applications
The benefits gained by using Kerberos for domain-based authentication are:
Delegated authentication.
1 of 3 10/17/2023, 10:28 AM
Kerberos Authentication Overview | Microsoft Learn https://learn.microsoft.com/en-us/windows-server/security/kerberos/k...
Interoperability.
Mutual authentication.
2 of 3 10/17/2023, 10:28 AM
Kerberos Authentication Overview | Microsoft Learn https://learn.microsoft.com/en-us/windows-server/security/kerberos/k...
See Also
Windows Authentication Overview
3 of 3 10/17/2023, 10:28 AM