Share via

Kerberos Ticket Wrong Client Domain

AbleTech 0 Reputation points
2026-05-29T13:22:13.2866667+00:00

Hello,

we recently switched from a hybrid AD environment to cloud-only using Entra Domain Services. We want clients to be Entra-joined (not Entra-registered) but also have a valid Kerberos ticket to easily access our internal NAS without re-entering login info. The NAS is domain-joined to the new Entra Domain so user login info is synchronized with the domain.

We can successfully Entra-join our devices and a kerberos ticket is fetched. But the ticket contains wrong information. Using klist from the machine, the ticket says Client: ******@new-domain.com @ OLDDOMAIN which of course then fails authentication with our NAS.

Some more infos: (1) The old domain and DomainController aren't active or available anymore, (2) we cleared all OnPremises* attributes for our users and (3) the ticket is correctly issued by the 'kerberos.microsoftonline.com' server. Still, the tickets have the old domain name as the client realm.

As we don't have direct access to Microsoft's Kerberos Server I am unsure how to proceed. We need help fixing this. Maybe the kerberos server still has the old domain cached and is using it as client realm.

Help is appreciated, since this is hindering us to upgrade devices from domain-registered to domain-joined.

Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Marcin Policht 91,150 Reputation points MVP Volunteer Moderator
    2026-05-29T18:04:36.98+00:00

    AFAIK, Microsoft Entra Domain Services does not support Cloud Kerberos Trust or passwordless Single Sign-On (SSO) from Entra-joined devices. One potential workaround would be to migrate NAS Data to Azure Files - but obviously that's a significant change which you might not be ready for


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.