Kerberos authentication certificate template

broken image
broken image

Smart card keys are created and stored using the Microsoft Smart Card Key Storage Provider.

broken image

Software-based keys are created and stored using the Microsoft Software Key Storage Provider.Windows generates and stores cryptographic keys using a software component called a key storage provider (KSP): For more information, see Remote Credential Guard.

broken image

Remote Credential Guard provides single sign-on (SSO) to RDP sessions using Kerberos authentication, and doesn't require the deployment of certificates. Consider using Remote Credential Guard instead of Windows Hello for Business for RDP sign-in.

broken image