On-prem AD vs Entra ID
What exists only on-prem, only in the cloud, and how they sync. The most common interview question of 2026.
| Topic | On-prem AD | Entra ID |
|---|---|---|
| Auth protocols | Kerberos, NTLM, LDAP | OAuth 2.0, OpenID Connect, SAML |
| Structure | Forest, domain, OU — hierarchical | Flat tenant, Administrative Units |
| Device policy | GPO | Intune (no GPO) |
| Conditional access | Not built in | Conditional Access + MFA |
| Just-in-time admin | Only with add-ons (PAM) | Built-in PIM |
| Who runs servers | You: DCs, backup, patching | Microsoft (SaaS) |
| Password Hash Sync | Password source | Gets hash of hash — simplest, most resilient |
| Pass-through Auth | Agent validates against DC | Depends on agent uptime |
| Federation (AD FS) | AD FS servers on-prem | Trusts AD FS — complex, Golden SAML target |
| What syncs | Users, groups, devices → via Entra Connect | GPO and OUs do not sync |