Certified: July 15, 2026
Solution Summary
This article describes the configuration steps involved in utilizing the Hybrid Domain Join feature for Microsoft.
Hybrid Microsoft Entra device join enables organizations to maintain a single device identity across both on-premises Active Directory and Microsoft Entra ID, simplifying device lifecycle management while supporting access to cloud resources.
Microsoft Entra Connect Sync synchronizes domain-joined devices from Active Directory to Microsoft Entra ID, making them eligible for hybrid Microsoft Entra device join.
When a hybrid join is initiated, RSA functions as the federated identity provider by authenticating the device using Kerberos-based Integrated Windows Authentication. Upon successful authentication, Microsoft Entra ID completes the device registration process and establishes the hybrid device identity.
Configuration Summary
This section contains instruction steps that show how to set up RSA Cloud Access Service (CAS) as the federated identity provider (IdP) for Microsoft Entra ID and enable Hybrid Join.
This document is not intended to suggest optimum installations or configurations. It is assumed that the reader has both working knowledge of all products involved, and the ability to perform the tasks outlined in this section. Administrators should have access to the product documentation for all products in order to install the required components.
All RSA and Microsoft components must be installed and working prior to the integration.
Configure CAS
Perform these steps to configure CAS as the Identity Provider (IdP) for Microsoft STS.
Procedure
- Navigate to Users > Identity Sources.
- Choose the Identity Source with the users and devices of your organization.
- Under Connection Settings, ensure the correct root is provided so Users and Computers reside there.
- Set the User Tag to mail.
- Under User Attributes, ensure UserPrincipalName and ObjectGUID are selected, and Policies and Apps are selected for both.
- Click Applications > Application Catalog.
- Search for Microsoft Office 365 STS and click Add.
- Under Basic Information, choose where to enable the application, provide a name for the Microsoft connector, and an optional description.
Notes
- The Hybrid Join Devices toggle option is displayed only if the application is hosted in the Cloud. It is not applicable for the application hosted in the Identity Router.
- Enable Hybrid Join Devices if the application should be configured for Hybrid Entra Join.
- Enabling the Entra Hybrid Domain Join will populate the Kerberos Configuration tab and Device Claims in the Entity Claims tab.
- On the Connection Profile page, in the Menu URL field, replace <RP_ENTITY_ID> with your Relying Party ID at the end of the page, which is urn:federation:MicrosoftOnline.
- Make a note of the WS-Federation Identity Provider (Issuer) URLs, as they will be required later when configuring federation on the Microsoft side.
- Navigate to the WS-Federation Response Signature section and import a private/public key pair for response signing and validation. If a key pair is not readily available, use the following procedure to generate a certificate bundle. If you already have one, skip ahead to the next step.
- Click Generate Certificate Bundle in the Response Signature section.
- Enter a common name for your Identity Router domain in the Common Name (CN) field.
- Click Generate and Download, save the certificate bundle ZIP file to a secure location, and extract its contents. The ZIP file contains a private key, a public certificate, and a certificate signing request.
- (Optional) If an MFA agent is needed to log in to the Windows VM with passwordless authentication methods, then upload the AD CA trusted certificate in the Hybrid Devices Certificates section.
- On the User Access page, select the required policy and click Next Step.
Note: For Hybrid Join devices, the access policies will not be applied. For No Access Allowed, the Hybrid Join flow will not work as expected. - In the Entity Claims section, configure the User Claims as follows:
- Claim A
- Source > Identity Source
- Claim Name > Immutable ID
- Identity Source > Select your Identity Source that will be used
- Property > objectGUID
- Claim B
- Source > Identity Source
- Claim Name > UPN
- Identity Source > Select your Identity Source that will be used
- Property > userPrincipalName
- Claim A
- If Hybrid Join Devices is enabled, configure the Device Claims section as shown in the following image, and click Next Step.
- When Hybrid Join Devices is enabled, provide the Kerberos configuration information required for RSA to validate Windows Kerberos tickets as part of the Hybrid Microsoft Entra Join process. After completing the configuration, click Next Step.
- SPN: Ensure that a Service Principal Name (SPN) has been registered in Active Directory for the RSA Identity Router service account. Configure the same SPN value.
- Realm: Specify the Kerberos realm associated with your Active Directory domain. In most environments, this is the Active Directory DNS domain name in uppercase.
- KDC: The Key Distribution Center that issues Kerberos tickets. In Active Directory environments, this is the Domain Controller hostname.
- Key Tab File: Upload the Kerberos Key tab file associated with the configured SPN and service account.
- (Optional) On the Portal Display page, fill in the details as required.
- Click Save and Finish.
- Click Publish Changes and wait for the operation to complete.
Configure Microsoft Entra
Configure Microsoft Entra Connect Sync
Perform these steps to configure Microsoft Entra Connect Sync.
Before You Begin
Before you set up CAS as the federated IdP for Microsoft Entra ID and enable hybrid join, you must complete the steps in the following Microsoft Entra Connect Sync procedure. This section configures Microsoft Entra Connect Sync to synchronize on-premises Active Directory with Microsoft Entra ID. During this process, user and device objects are synchronized to Microsoft Entra, providing the foundation required for Hybrid Microsoft Entra Join.
Procedure
- Log in to the Microsoft Entra admin center https://entra.microsoft.com/
- Search for Microsoft Entra Connect in the search bar and choose it from the list of Services.
- Choose Connect Sync in the left pane and click Download Microsoft Connect Sync.
- Run the installer for Microsoft Entra Connect and agree to the Terms and Conditions on the first screen.
- In the Express Settings step, click Customize.
- On the User sign-in screen, choose Do not configure as the Sign On method.
- On the Connect to Microsoft Entra ID screen, enter your Entra ID account and log in to an administrator account.
- On the Connect your directories screen, ensure the AD domain displayed for FOREST is the AD domain intended to use for hybrid join and click Add Directory.
The AD forest account window opens. - Select Create new AD account and enter the admin AD account sign-on credentials.
- Click OK.
- After providing the Active Directory Enterprise Administrator credentials, verify that the on-premises Active Directory forest to be synchronized with Microsoft Entra ID is listed under CONFIGURED DIRECTORIES with a green check mark.
- In the Connect your directories step, click Next.
- Verify that the Active Directory UPN Suffix is displayed. If the UPN suffix has not been added as a verified domain in Microsoft Entra ID, it will be shown as Not Added. In a production environment, the AD UPN suffix should typically match a verified Microsoft Entra domain to allow users to sign in with the same username in both environments.
- On the Domain and OU filtering screen, select the Active Directory domains and Organizational Units (OUs) to be synchronized with Microsoft Entra ID and click Next. Ensure that any OU containing users or computer objects intended for Hybrid Microsoft Entra Join is included.
- In the Identifying users step, retain the default settings and click Next.
The default Let Azure manage the source anchor setting means Entra ID will identify users with the sourceAnchor attribute of mS-DS-ConsistencyGuid. - In the Filtering step, choose on of the following options:
- Synchronize all users and devices: Syncs all users and devices to Entra ID.
- Synchronize selected: Enter a name or distinguished name (DN) of a group to sync to Entra ID.
- On the Optional Features screen, leave all the checkboxes cleared and click Next.
- On the Configure screen, select the Start the synchronization process when configuration completes checkbox and click Install.
Configure Microsoft Entra ID Federation with RSA
This section describes the configuration steps in Microsoft Entra for federating an organization’s domain with CAS. Once the federation trust is established, Microsoft Entra delegates authentication requests, including those generated during the Hybrid Microsoft Entra Join process, to RSA for authentication.
Procedure
- Log in to the Microsoft Entra admin center https://entra.microsoft.com/
- In the left navigation pane under Microsoft Entra ID, select Domain names and verify that your domain appears in the Custom domain names list. If the domain is not listed, click Add custom domain and follow the prompts to verify and add your domain.
- Run Windows PowerShell as an administrator and connect to Microsoft Graph with the following command. Sign in using a Microsoft Entra Global Administrator (or another account with sufficient permissions to manage domain federation).
Note: This admin account should be in a separate domain from the one that will be federated (for example, a member of the default domain that is provided by Microsoft).Connect-MgGraph - Retrieve all domains for the company (verified or unverified) to identify the domain that should be federated.
Get-MgDomain - Run the following commands in a PowerShell environment. Most of the values come from the CAS configuration section.
- DomainId: Enter the domain identified in the previous step that will be federated by RSA.
- SigningCertificate: Configure the signing certificate by following these steps:
- Download the certificate to a folder (for example, C:\Users\my.name\Downloads).
- Use the following PowerShell commands to process the certificate and assign it to the certData variable.
- If entering the command manually, ensure the character in "r|n" is a backtick, not a single quote.
$cert = "C:\Users\my.name\Downloads\IDPSigningCertificate.pem" $certData = $(Get-Content -Path $cert -Raw) -replace"`r|`n|-----BEGIN CERTIFICATE-----|----- END CERTIFICATE-----",""
- PassiveSigninUri: The Passive Endpoint URL in the WS-Federation Identity Provider section in RSA configuration.
- ActiveSignInUri: The Active Endpoint URL in the WS-Federation Identity Provider section in RSA configuration.
- MetadataExchangeUri: The Mex Endpoint URL in the WS-Federation Identity Provider section in RSA configuration.
- IssuerUri: The Identity Provider Entity ID in the WS-Federation Identity Provider section in RSA configuration.
- FederatedIdpMfaBehavior: acceptIfMfaDoneByFederatedIdp
- PreferredAuthenticationProtocol: wsFed
- PromptLoginBehavior: nativeSupport
New-MgDomainFederationConfiguration -DomainId yourdomain.com -SigningCertificate $certData -PassiveSignInUri <> -ActiveSignInUri <> -MetadataExchangeUri <> -IssuerUri <> -FederatedIdpMfaBehavior "acceptIfMfaDoneByFederatedIdp" -PreferredAuthenticationProtocol "wsFed" -PromptLoginBehavior "nativeSupport"
- After applying the new domain federation configuration, you will be prompted to provide the internal domain federation ID. To retrieve this value, run the following command:
Get-MgDomainFederationConfiguration -DomainId "yourdomainname.com" - To verify if the domain is configured successfully, run the following command:
Get-MgDomainFederationConfiguration | Format-List * - If you need to un-federate a domain, run the following command:
Update-MgDomain -DomainId "yourdomainname.com" -AuthenticationType "Managed"
Configure Microsoft Entra Hybrid Join
After synchronization and federation are configured, use this section to enable Hybrid Microsoft Entra Join by configuring the required device registration settings, including the Service Connection Point (SCP). This configuration allows Windows devices to automatically register with Microsoft Entra ID while remaining joined to on-premises.
Procedure
- Open Microsoft Entra Connect, and then click Configure.
- On the Additional tasks page, select Configure device options, and then click Next.
- On the Overview page, click Next.
- On the Connect to Microsoft Entra ID page, enter the credentials of a Hybrid Identity Administrator for your Microsoft Entra tenant, and then click Next.
- On the Device options page, select Configure Microsoft Entra hybrid join, and then click Next.
- On the SCP page, complete the following steps, and then click Next:
- Select the forest.
- Select the authentication service. Select the verified federated Microsoft Entra domain (for example, company.com) that was configured in the previous Federation section.
- Click Add to enter the enterprise administrator credentials for the selected Active Directory forest.
- On the Device systems page, select the operating systems that the devices in your Active Directory environment use, and then click Next.
- In the Federation step, click Next.
- In the Configure step, click Configure and click Exit when the installation completes.
Disable Fallback Sync in Windows
Recent versions of Windows include a fallback synchronization mechanism that is used when a Hybrid Microsoft Entra Join request cannot be completed through the federated IdP. To verify that the hybrid join process is configured correctly, consider disabling fallback synchronization on the device. This ensures that Identity Router (IDR), acting as the federated IdP, processes Hybrid Microsoft Entra Join requests and other authentication scenarios that rely on the STS flow.
Procedure
- On a Windows-based computer to be joined to the cloud, open Registry Editor.
- Go to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CDJ and locate the FallbackToSyncJoin DWORD, as shown in the following image.
- If the CDJ key does not exist in Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion, create this new key by right-clicking in the CurrentVersion folder and clicking New > Key.
- If the FallbackToSyncJoin DWORD does not exist in the CDJ key folder, create this new DWORD by right-clicking in the CDJ key folder and clicking New > DWORD (32-bit) Value.
- To disable fallback sync:
- Double-click FallbackToSyncJoin DWORD.
- Set Value data to 0.
- Click OK.
- To re-enable fallback sync:
- Double-click FallbackToSyncJoin DWORD.
- Set Value data to 1.
- Click OK.
The configuration is complete.
RSA Terminology Changes
The following table describes the differences in the terminologies used in the different versions of RSA products and components.
| Previous Version | New Version | Examples/Comments |
| Cloud Authentication Service | Cloud Access Service | |
| Token | OTP Credential | SecurID OTP Credential |
| Authenticator | Hardware Authenticator | |
| Tokencode | OTP | SecurID OTP, SMS OTP, Voice OTP |
| Access Code | Emergency Access Code | |
| SecurID Authenticate app | RSA Authenticator app | RSA Authenticator app for iOS and Android, RSA Authenticator app for Windows |
| Device | Authenticator | Register an authenticator |
| Company ID | Organization ID | |
| Account | Credential | |
| Device Serial Number | Binding ID |
Certification Details
CAS
Microsoft Entra
Known Issues
No known issues.
Related Articles
Microsoft SharePoint - SSO Agent - WS-Fed Configuration - RSA Ready SecurID Access Implementation Guide 35Number of Views Microsoft SharePoint 2016 - WS-Fed SSO Agent Configuration - RSA Ready Implementation Guide 25Number of Views Tape Silo w/Encryption showing key error 9Number of Views Workday Web Service Identity Collector (IDC) on WebSphere fails with 'Failed to add WS-Security header to request' error i… 88Number of Views SSOAgent - WS-FedConfiguration - Microsoft SharePoint 2019 RSA Ready SecurID Access Implementation Guide 34Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update How to Forward RSA Authentication Manager 8.4 or Later Logs to Multiple Syslog Servers Using rsyslog RSA Authentication Manager 8.9 Patches and Hotfixes Readme