This blog talks about how to go passwordless when authenticating with Remote Desktop.
Updated Mar 28, 2025
Version 2.0I have been trying to explore this solution but encountered a Challenge. How can we authenticate on RDP for High Privileged Accounts from Onpremise AD? Such as Domain Admins. the WHFB does not work for such type of accounts because the password hash is not synced to Azure. Do you have any idea how to deal with this?
igorscoff
The Denied RODC Password Replication Group plays a critical role in securing both traditional Read-Only Domain Controllers (RODCs) and Azure AD Kerberos environments. ;-)
https://wiki.winadmins.io/en/active-directory/whfb-cloud-kerberos-trust
https://0xdeaddood.rocks/2021/11/11/the-kerberos-key-list-attack-the-return-of-the-read-only-domain-controllers/