How to migrate apps which has NTLM, Kerberos and LDAP integrated on on-premises environments to Entra ID and what all things we need to take care of so that we dont loose apps access and configurations as well?

Mytoast Admin 285 Reputation points
2025-01-31T08:42:35.7866667+00:00

How to migrate apps which has NTLM, Kerberos and LDAP integrated on on-premises environments to Entra ID and what all things we need to take care of so that we don't loose apps access and configurations as well?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,622 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,836 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,072 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marti Peig 875 Reputation points Microsoft Employee
    2025-01-31T11:17:57.6866667+00:00

    Hi @Mytoast Admin ,

    Thanks for reaching out, and posting your question in Q&A. Migration of an app to Entra ID based authentication is never a 'one size fits all' thing. Each application has it particularities and these should be considered in detail before choosing the right migration strategy. However, in general you can use the following as reference...

    For NTLM/Kerberos-based Apps

    Option 1: Azure AD Kerberos (Hybrid Kerberos Authentication)

    • Azure AD Kerberos allows cloud authentication for apps that still rely on Kerberos.
    • Requires Hybrid AD Join for devices.

    Option 2: Modern Authentication (Preferred)

    • Migrate apps to Entra ID authentication using OAuth 2.0, OpenID Connect, or SAML.
    • Configure Entra ID Application Proxy if the app must remain on-prem but needs modern auth.

    Option 3: Use Windows 365 or Azure Virtual Desktop

    • If the app cannot be modernized but still needs on-prem access, use Cloud PCs.

    B. For LDAP-based Apps

    Option 1: Azure AD DS (Managed Domain Services)

    • Azure AD DS provides LDAP, Kerberos, and NTLM support in the cloud.
    • Requires synchronization with Entra ID.

    Option 2: Modern Authentication

    • Replace LDAP authentication with Azure AD authentication via OAuth 2.0/SAML.
    • Consider using Microsoft Graph API for directory queries instead of direct LDAP calls.

    As usual, if this answers your question, do click Accept Answer and Yes for what if this answer was helpful. And, if you have any further queries do let us know. 

    Cheers


  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.