On-premises DS is built for an internal network: , , , and domain-joined computers. Entra ID (formerly Azure AD) is built for the internet: OAuth 2.0, OIDC, SAML, and SaaS applications. It's not 'AD in the cloud' — it's a different system with the same role.
Key Differences
- Structure: DS is built with OU and ; Entra ID is flat — Users, Groups, and Administrative Units.
- Protocols: DS — //; Entra ID — OAuth2/OIDC/SAML/SCIM.
- Policy Management: DS — ; Entra ID — Intune Policies and Conditional Access.
- Access: DS requires network line of sight (or VPN); Entra ID is available from anywhere on the internet.
On-prem AD DS with Kerberos, LDAP and GPO on the left, Entra ID with OAuth2, OIDC and SAML on the right. Between them the Entra Connect or Cloud Sync server — a Tier 0 asset because it holds DCSync-level rights. Below, three authentication models: PHS syncs the password hash so the cloud verifies; PTA has an agent forward verification to an on-prem DC; ADFS federates through your own token server and carries the Golden SAML risk. Bottom line: Hybrid Join means domain joined for GPO plus Entra joined for cloud SSO.
Hybrid Models
- Password Hash Sync (PHS) — The simplest and most resilient: a hash of the hash is synchronized to the cloud.
- Pass-through Authentication (PTA) — Authentication itself is performed against a local DC via an Agent.
- Federation (ADFS) — A local federation server issues Tokens; complex and has a large attack surface (Golden SAML).
- Entra Connect / Cloud Sync — The component that synchronizes users and groups from DS to Entra ID.