In most organizations users are created in on-prem DS but also need to sign in to Microsoft 365. The bridge is Entra Connect (or Cloud Sync): an agent that synchronizes users and groups from the domain to the cloud.
Three authentication methods
- PHS (Password Hash Sync) — the password hash is synced to the cloud. Simplest and most resilient: sign-in works even when the on-prem DC is down.
- PTA (Pass-through Authentication) — the password is validated against the on-prem DC via an agent. No hash in the cloud, but it depends on on-prem availability.
- Federation ( FS) — authentication is redirected to an on-prem AD FS server. Most flexible, but the most expensive and complex to maintain.
Device join
- Azure Join — the device exists only in the cloud; good for remote staff.
- Hybrid Azure Join — the device is domain-joined and cloud-registered; gives SSO to both worlds.
- Entra Registered — a personal (BYOD) device with limited access.
On-prem AD DS with Kerberos, LDAP and GPO on the left, Entra ID with OAuth2, OIDC and SAML on the right. Between them the Entra Connect or Cloud Sync server — a Tier 0 asset because it holds DCSync-level rights. Below, three authentication models: PHS syncs the password hash so the cloud verifies; PTA has an agent forward verification to an on-prem DC; ADFS federates through your own token server and carries the Golden SAML risk. Bottom line: Hybrid Join means domain joined for GPO plus Entra joined for cloud SSO.