# Review password-hash prerequisites before using Entra Domain Services for RDS

> Which identity prerequisites need review before an RDS deployment uses Microsoft Entra Domain Services?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:53+00:00
- Modified: 2026-09-08T18:26:32+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which identity prerequisites need review before an RDS deployment uses Microsoft Entra Domain Services?

## Potentially affected

Administrators evaluating Microsoft Entra Domain Services for Remote Desktop Services.

## DSE recommendation

Document the proposed identity path, the organizational decision on synchronized password hashes, and the affected user population.

## Article

## Source facts

Microsoft documents using Entra Domain Services in an RDS deployment in place of Windows Server Active Directory. Its prerequisites require the necessary password hashes to be available in Microsoft Entra ID. For identities originating on premises, the source calls for permitting hash synchronization and storage, and notes password-reset requirements after the configuration change. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds).

## Applicability

Identify where the intended user identities originate and have the identity owner assess the required password-hash handling. Review the linked current Entra Domain Services guidance for the actual tenant and account population. Treat this as an identity-design decision, not simply an RDS installation option.

## DSE recommendation

Document the proposed identity path, the organizational decision on synchronized password hashes, and the affected user population. Assign responsibility for any required password changes and user communications. Pilot with a small authorized set before placing a production collection on the managed domain. Keep the directory prerequisite assessment separate from the RDS application and capacity plan.

## Verification

Verify that pilot identities can perform the intended domain and RDS authentication after the required preparation. Include an account that has not completed the prerequisite steps and document its outcome. Confirm user communications and support ownership before expanding the deployment. Record identity failures separately from collection or application failures.

## Official references

[Microsoft Learn: Microsoft Entra Domain Services and Remote Desktop Services](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds). Source reviewed September 8, 2026.

## Primary reference

- Name: Microsoft Entra Domain Services and Remote Desktop Services
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review password-hash prerequisites before using Entra Domain Services for RDS,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-198-review-password-hash-prerequisites-before-using-entra-domain-services-for-rds/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
