Microsoft Azure offers Entra Domain Services as managed domain services.
More details can be seen here:
Overview of MS Entra Domain Services - Microsoft Entra ID
Does Safeguard Authentication Services work with Microsoft Entra Domain Services at this time?
Yes, Authentication Services will work in an environment that is using Entra Domain Services as an authenticator; however, there are specific caveats and limitations compared to a traditional Active Directory setup and configuration.
1) The join must be performed with a user account that is a member of the "AAD DC Administrators" group.
Note: Once a user is added to this group, it can take up to 24 hours before they will be able to join.
2) The Q.A.C install requires a Windows machine to be joined to the domain and the tools (RSAT, GPMC) installed there.
However, the Authentication Services cannot register the display specifiers.
3) Writing to Entra Domain Services is not possible; the only exception to this rule is creating the computer object. This includes but is not limited to creating users and groups. Essentially, a read-only environment for syncing users from Entra ID.
4) The Unix account configuration is handled from the Windows Machine with RSAT; it is not available from the Entra ID portal.
5) Multi-factor authentication is not applied to the Linux/Unix machines.
6) The user password change is not available from the Linux/Unix machine, but the password change prompt will appear with expiration or a required password change.
7) The Entra Domain Services limitation does not allow the creation of a user, group, or service account from ADUC or a Unix/Linux machine.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center