Skip to main content
AD Academy

On-prem AD vs Entra ID

What exists only on-prem, only in the cloud, and how they sync. The most common interview question of 2026.

TopicOn-prem ADEntra ID
Auth protocolsKerberos, NTLM, LDAPOAuth 2.0, OpenID Connect, SAML
StructureForest, domain, OU — hierarchicalFlat tenant, Administrative Units
Device policyGPOIntune (no GPO)
Conditional accessNot built inConditional Access + MFA
Just-in-time adminOnly with add-ons (PAM)Built-in PIM
Who runs serversYou: DCs, backup, patchingMicrosoft (SaaS)
Password Hash SyncPassword sourceGets hash of hash — simplest, most resilient
Pass-through AuthAgent validates against DCDepends on agent uptime
Federation (AD FS)AD FS servers on-premTrusts AD FS — complex, Golden SAML target
What syncsUsers, groups, devices → via Entra ConnectGPO and OUs do not sync