Back to Projects
Business Systems House 2025

Azure AD Application Proxy & SSO Hybrid Integration

Azure AD Application Proxy & SSO Hybrid Integration
Azure AD Application Proxy Entra ID Single Sign-On Kerberos Constrained Delegation (KCD)

Azure AD Application Proxy & SSO Hybrid Integration

Architected secure cloud publishing for on-premises internal portals, enabling SSO and MFA without exposing direct inbound firewall ports.

Key Features & Implementation

  • Inbound Port Elimination: Utilized outbound-only Azure AD App Proxy connector services to route external traffic securely.
  • Kerberos Constrained Delegation (KCD): Configured KCD to seamlessly authenticate cloud-authenticated users to internal Windows-authenticated web apps.
  • Conditional Access Binding: Enforced device compliance and geo-blocking policies on all external application access attempts.
ROOT ACCESS GRANTED