Skip to main content
AD Academy
Cloud Computing: Architecture and Security
Beginner14 minLast updated: Topic 4 of 8

Identity in the Cloud: Entra ID vs. Active Directory

The difference between on-premises directory and cloud identity, and hybrid models.

Not read

What you will learn here

  • Key Differences
  • Hybrid Models
  • The difference between on-premises directory and cloud identity, and hybrid models.

Worth reading first:Shared Responsibility Model (Microsoft Azure)

On-premises DS is built for an internal network: , , , and domain-joined computers. Entra ID (formerly Azure AD) is built for the internet: OAuth 2.0, OIDC, SAML, and SaaS applications. It's not 'AD in the cloud' — it's a different system with the same role.

Key Differences

  • Structure: DS is built with OU and ; Entra ID is flat — Users, Groups, and Administrative Units.
  • Protocols: DS — //; Entra ID — OAuth2/OIDC/SAML/SCIM.
  • Policy Management: DS — ; Entra ID — Intune Policies and Conditional Access.
  • Access: DS requires network line of sight (or VPN); Entra ID is available from anywhere on the internet.

On-prem AD DS with Kerberos, LDAP and GPO on the left, Entra ID with OAuth2, OIDC and SAML on the right. Between them the Entra Connect or Cloud Sync server — a Tier 0 asset because it holds DCSync-level rights. Below, three authentication models: PHS syncs the password hash so the cloud verifies; PTA has an agent forward verification to an on-prem DC; ADFS federates through your own token server and carries the Golden SAML risk. Bottom line: Hybrid Join means domain joined for GPO plus Entra joined for cloud SSO.

Short and clear

  • AD DS speaks Kerberos/LDAP inside the network; Entra ID speaks OAuth2/OIDC/SAML over the Internet.
  • Entra Connect is the bridge — which makes it a Tier 0 asset with DCSync-level rights.
  • PHS is simplest and most resilient, PTA verifies against an on-prem DC, ADFS is the most complex and exposed to Golden SAML.
  • Hybrid Join = GPO from the domain plus SSO to cloud apps.

Real-life exampleA domain-joined employee opens Teams from home with no VPN: the token comes from Entra ID, while group policy still arrives from the DC when on the network.

Hybrid Models

  • Password Hash Sync (PHS) — The simplest and most resilient: a hash of the hash is synchronized to the cloud.
  • Pass-through Authentication (PTA) — Authentication itself is performed against a local DC via an Agent.
  • Federation (ADFS) — A local federation server issues Tokens; complex and has a large attack surface (Golden SAML).
  • Entra Connect / Cloud Sync — The component that synchronizes users and groups from DS to Entra ID.

Check yourself

Which authentication protocol is used by Entra ID (and not by on-premises AD DS)?

Why is the Entra Connect server considered Tier 0?

Was this page helpful?