Archive

Article archive

Every article published on Sentinel Identity, organized as a searchable reading archive for Microsoft identity engineers and IT administrators.

Hybrid Sign-In Architecture

A technical guide to Password Hash Synchronization, Pass-Through Authentication, and federation with AD FS or PingFederate, centered on where validation really happens.

Core Authentication Methods

A technical guide to Kerberos, NTLM, LDAP bind, passkeys, certificate-based authentication, and Windows Hello for Business, focused on what each method proves and how the backend validates it.

Authentication Protocols Explained

A technical guide to the major authentication protocols and sign-in models used in Microsoft environments, including Kerberos, NTLM, LDAP bind, SAML, WS-Federation, OAuth 2.0, OpenID Connect, passkeys, certificate-based authentication, AD FS, and Microsoft Entra sign-in models.

Passkey Sign-In and Rollout

A technical guide to Microsoft Entra passkey sign-in, including same-device and cross-device flows, compatibility dependencies, and rollout design.

Passkey Registration

A technical guide to Microsoft Entra passkey registration on Windows and mobile, with a focus on credential issuance, MFA bootstrap, platform differences, and backend policy checks.

Passkey Policy and Attestation

A technical guide to Microsoft Entra passkey profiles, AAGUID restrictions, attestation behavior, and the control-plane logic behind passkey governance.

Entra Backup and Recovery

A technical document for Microsoft Entra administrators covering how Microsoft Entra Backup and Recovery works, what it can recover, supported objects and properties, difference reports, recovery behavior, soft deletion, troubleshooting, and operational design guidance.

AADSTS50020 Sign-In Failures

A detailed technical guide to AADSTS50020 in Microsoft Entra ID, including resource-tenant identity resolution, invitation redemption, cross-tenant access, and external identity design.

Windows Device Join Failures

A detailed technical guide to Microsoft Entra join and registration failures on Windows, including device registration service flow, pending objects, dsregcmd analysis, and downstream impact on compliance and PRT.

Why Compliant Devices Still Get Blocked

A detailed technical guide to why Microsoft Entra can block a sign-in from an Intune-compliant device, including device identity proof, browser support, client certificate behavior, and Conditional Access evaluation.

Passkey Troubleshooting Guide

A technical troubleshooting guide for Microsoft Entra passkeys covering registration failures, Conditional Access loops, Bluetooth issues, orphaned passkeys, compatibility gaps, and Authenticator-specific problems.