Share via

Microsoft Entra Seamless SSO vs Primary Refresh Token for a Hybrid Enivronment - what is the best option?

Gabe 65 Reputation points
2025-12-19T19:56:42.5333333+00:00

In our environment we are hyrbid joined and we currently utilize Seamless-SSO with our AADCONNECT server. We have a script that we run to rollover the kerberos key every month, and am looking for modern and/or updated ways to see if this is still necessary within the environment.

After researching for days on end, I've been able to find that we can use a Primary Refresh Token for SSO (https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa) instead of Seamless-SSO for Microsoft Entra Connect.

This information is quite confusing as I do not understand if we can use this in replacement of kerberos rollover or would it be better to remain on Seamsless-SSO?

Also, would there be any possible issues if we were to switch over to PRT from Seamless-SSO in terms of downtime, etc?

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author

  1. Rahul Jindal 11,631 Reputation points
    2025-12-20T03:52:05.68+00:00

    PRT is the modern SSO mechanism and recommended for hybrid environments. Seamless SSO is only needed for initial silent auth. Consider removing it and moving to PRT. That way you will not be required to rollover the Kerberos on a monthly basis.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.