Useful URL for Determining the Domain Type
At times, there arises a necessity to ascertain whether a domain is federated or managed. This determination can be effortlessly performed using the provided URL:
https://login.microsoftonline.com/common/UserRealm/?user=@<domainName>&api-version=1.0&checkForMicrosoftAccount=false
Substitute <domainName> in the URL with the domain name you want to query.
Managed Domain:
data:image/s3,"s3://crabby-images/1a2ba/1a2ba73a8bdcb39d9f70d0bfb89f7093937ad19d" alt=""
Federated Domain with WSTrust:
data:image/s3,"s3://crabby-images/5f876/5f876ca4b802dd3837ad84bb85a84fb95f44173d" alt=""
Federated Domain with SAML20:
data:image/s3,"s3://crabby-images/37e26/37e26ab36e6540fa26f8d18e69d66f2ad2a9683e" alt=""
3rd party identity providers need to support the WS-Trust protocol to enable PRT issuance on Windows 10 or newer devices. Without WS-Trust, PRT cannot be issued to users on Hybrid Azure AD joined or Azure AD joined devices.
Primary Refresh Token (PRT) and Azure Active Directory – Microsoft Entra | Microsoft Learn