{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/",
        "slug": "dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/"
        },
        "title": "Review password-hash prerequisites before using Entra Domain Services for RDS",
        "summary": "Which identity prerequisites need review before an RDS deployment uses Microsoft Entra Domain Services?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:53+00:00",
        "modified_at": "2026-09-08T18:26:32+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 224,
        "potentially_affected": "Administrators evaluating Microsoft Entra Domain Services for Remote Desktop Services.",
        "dse_recommendation": "Document the proposed identity path, the organizational decision on synchronized password hashes, and the affected user population.",
        "primary_source": {
            "name": "Microsoft Entra Domain Services and Remote Desktop Services",
            "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents using Entra Domain Services in an RDS deployment in place of Windows Server Active Directory. Its prerequisites require the necessary password hashes to be available in Microsoft Entra ID. For identities originating on premises, the source calls for permitting hash synchronization and storage, and notes password-reset requirements after the configuration change. <a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify where the intended user identities originate and have the identity owner assess the required password-hash handling. Review the linked current Entra Domain Services guidance for the actual tenant and account population. Treat this as an identity-design decision, not simply an RDS installation option.</p>\n<h2>DSE recommendation</h2>\n<p>Document the proposed identity path, the organizational decision on synchronized password hashes, and the affected user population. Assign responsibility for any required password changes and user communications. Pilot with a small authorized set before placing a production collection on the managed domain. Keep the directory prerequisite assessment separate from the RDS application and capacity plan.</p>\n<h2>Verification</h2>\n<p>Verify that pilot identities can perform the intended domain and RDS authentication after the required preparation. Include an account that has not completed the prerequisite steps and document its outcome. Confirm user communications and support ownership before expanding the deployment. Record identity failures separately from collection or application failures.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Microsoft Entra Domain Services and Remote Desktop Services</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft documents using Entra Domain Services in an RDS deployment in place of Windows Server Active Directory. Its prerequisites require the necessary password hashes to be available in Microsoft Entra ID. For identities originating on premises, the source calls for permitting hash synchronization and storage, and notes password-reset requirements after the configuration change. Microsoft Learn.\nApplicability\nIdentify where the intended user identities originate and have the identity owner assess the required password-hash handling. Review the linked current Entra Domain Services guidance for the actual tenant and account population. Treat this as an identity-design decision, not simply an RDS installation option.\nDSE recommendation\nDocument the proposed identity path, the organizational decision on synchronized password hashes, and the affected user population. Assign responsibility for any required password changes and user communications. Pilot with a small authorized set before placing a production collection on the managed domain. Keep the directory prerequisite assessment separate from the RDS application and capacity plan.\nVerification\nVerify that pilot identities can perform the intended domain and RDS authentication after the required preparation. Include an account that has not completed the prerequisite steps and document its outcome. Confirm user communications and support ownership before expanding the deployment. Record identity failures separately from collection or application failures.\nOfficial references\nMicrosoft Learn: Microsoft Entra Domain Services and Remote Desktop Services. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft documents using Entra Domain Services in an RDS deployment in place of Windows Server Active Directory. Its prerequisites require the necessary password hashes to be available in Microsoft Entra ID. For identities originating on premises, the source calls for permitting hash synchronization and storage, and notes password-reset requirements after the configuration change. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds).\n\n## Applicability\n\nIdentify where the intended user identities originate and have the identity owner assess the required password-hash handling. Review the linked current Entra Domain Services guidance for the actual tenant and account population. Treat this as an identity-design decision, not simply an RDS installation option.\n\n## DSE recommendation\n\nDocument the proposed identity path, the organizational decision on synchronized password hashes, and the affected user population. Assign responsibility for any required password changes and user communications. Pilot with a small authorized set before placing a production collection on the managed domain. Keep the directory prerequisite assessment separate from the RDS application and capacity plan.\n\n## Verification\n\nVerify that pilot identities can perform the intended domain and RDS authentication after the required preparation. Include an account that has not completed the prerequisite steps and document its outcome. Confirm user communications and support ownership before expanding the deployment. Record identity failures separately from collection or application failures.\n\n## Official references\n\n[Microsoft Learn: Microsoft Entra Domain Services and Remote Desktop Services](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review password-hash prerequisites before using Entra Domain Services for RDS",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/",
                "headline": "Review password-hash prerequisites before using Entra Domain Services for RDS",
                "description": "Which identity prerequisites need review before an RDS deployment uses Microsoft Entra Domain Services?",
                "abstract": "Which identity prerequisites need review before an RDS deployment uses Microsoft Entra Domain Services?",
                "articleBody": "Source facts\nMicrosoft documents using Entra Domain Services in an RDS deployment in place of Windows Server Active Directory. Its prerequisites require the necessary password hashes to be available in Microsoft Entra ID. For identities originating on premises, the source calls for permitting hash synchronization and storage, and notes password-reset requirements after the configuration change. Microsoft Learn.\nApplicability\nIdentify where the intended user identities originate and have the identity owner assess the required password-hash handling. Review the linked current Entra Domain Services guidance for the actual tenant and account population. Treat this as an identity-design decision, not simply an RDS installation option.\nDSE recommendation\nDocument the proposed identity path, the organizational decision on synchronized password hashes, and the affected user population. Assign responsibility for any required password changes and user communications. Pilot with a small authorized set before placing a production collection on the managed domain. Keep the directory prerequisite assessment separate from the RDS application and capacity plan.\nVerification\nVerify that pilot identities can perform the intended domain and RDS authentication after the required preparation. Include an account that has not completed the prerequisite steps and document its outcome. Confirm user communications and support ownership before expanding the deployment. Record identity failures separately from collection or application failures.\nOfficial references\nMicrosoft Learn: Microsoft Entra Domain Services and Remote Desktop Services. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:53+00:00",
                "dateModified": "2026-09-08T18:26:32+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review password-hash prerequisites before using Entra Domain Services for RDS"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 224,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Entra Domain Services and Remote Desktop Services",
                    "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds"
                }
            }
        ]
    }
}