Hello,
We are conducting an internal privacy and security compliance review and would like to confirm how Microsoft Entra ID stores and protects user passwords and authentication information.
Service / Environment
- Microsoft Entra ID
- Microsoft Entra Connect is used in our environment
- We have not yet confirmed whether the authentication method is Password Hash Synchronization (PHS), Pass-through Authentication (PTA), or Federation
Question
Could you please clarify the following regarding Microsoft Entra ID?
- Are user passwords stored in Microsoft Entra ID in plaintext or in any reversibly encrypted form, or are they stored only as non-reversible hash-derived values?
- If Password Hash Synchronization (PHS) is used, what password-related value is transmitted from on-premises Active Directory to Microsoft Entra ID, and how is that value stored in Entra ID?
- When users authenticate to Microsoft Entra ID, how are passwords and other authentication information protected while being transmitted over the network? For example, is TLS or another secure encryption protocol used?
- Does the password storage or transmission mechanism differ depending on whether PHS, PTA, or Federation is used?
Our goal is to verify whether the following statements are technically correct for internal compliance documentation:
“User passwords are not stored in plaintext or in a reversibly encrypted form in Microsoft Entra ID, but are stored in a non-reversible form.”
“Authentication information transmitted over a network is protected through encrypted communication.”
If possible, could you also provide official Microsoft documentation that describes the password storage, synchronization, and transmission protection mechanisms?
Thank you.Hello,
We are conducting an internal privacy and security compliance review and would like to confirm how Microsoft Entra ID stores and protects user passwords and authentication information.
Service / Environment
- Microsoft Entra ID
- Microsoft Entra Connect is used in our environment
- We have not yet confirmed whether the authentication method is Password Hash Synchronization (PHS), Pass-through Authentication (PTA), or Federation
Question
Could you please clarify the following regarding Microsoft Entra ID?
- Are user passwords stored in Microsoft Entra ID in plaintext or in any reversibly encrypted form, or are they stored only as non-reversible hash-derived values?
- If Password Hash Synchronization (PHS) is used, what password-related value is transmitted from on-premises Active Directory to Microsoft Entra ID, and how is that value stored in Entra ID?
- When users authenticate to Microsoft Entra ID, how are passwords and other authentication information protected while being transmitted over the network?
For example, is TLS or another secure encryption protocol used?
- Does the password storage or transmission mechanism differ depending on whether PHS, PTA, or Federation is used?
Our goal is to verify whether the following statements are technically correct for internal compliance documentation:
“User passwords are not stored in plaintext or in a reversibly encrypted form in Microsoft Entra ID, but are stored in a non-reversible form.”
“Authentication information transmitted over a network is protected through encrypted communication.”
If possible, could you also provide official Microsoft documentation that describes the password storage, synchronization, and transmission protection mechanisms?
Thank you.