Azure AD DS : user certificate for ldap authentication

Toyoshima Kaori 21 Reputation points
2021-11-10T04:12:44.677+00:00

Hi Experts,

I'm using Azure AD DS as LDAP(S) authentication server.
Our AADDS is not in hybrid mode as we don't have on-prem AD in this environment.
My question is if Azure AD DS can manage user certificate to support certificate-based authentication, in this case?
I can see published certificate extension belongs to AD DS user, but not sure how to manage this.

Best Regards,
Kaori

147976-%E3%82%B9%E3%82%AF%E3%83%AA%E3%83%BC%E3%83%B3%E3%82%B7%E3%83%A7%E3%83%83%E3%83%88-2021-11-10-130608.png

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. AmanpreetSingh-MSFT 56,946 Reputation points Moderator
    2021-11-11T15:57:41.593+00:00

    Hi @Toyoshima Kaori • Thank you for reaching out.

    For this purpose, you need to have Read userCertificate and Write userCertificate permissions but on the managed domains, you aren't granted administrative privileges and you cannot delegate/assign these permissions. Group membership of users and groups that are synchronized from Azure Active Directory to Azure AD Domain Services cannot be modified because their source of origin is Azure Active Directory.

    Within the managed domain, Domain Administrator and Enterprise Administrator privileges aren't available for you to use. Even in hybrid deployments, members of the domain administrator or enterprise administrator groups in your on-premises Active Directory are also not granted domain/enterprise administrator privileges on the managed domain.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.