Skip to main content
AD Academy
Microsoft Entra ID (Azure AD)
Intermediate14 minLast updated: Topic 2 of 6

Hybrid identity: Entra Connect, PHS, PTA and federation

How to connect an on-prem domain to Entra ID and how the sign-in methods differ.

Not read

What you will learn here

  • What Entra Connect Sync does
  • The difference between PHS, PTA and Federation
  • What Hybrid Azure AD Join is

Worth reading first:What Entra ID is and how it differs from AD DS

In most organizations users are created in on-prem DS but also need to sign in to Microsoft 365. The bridge is Entra Connect (or Cloud Sync): an agent that synchronizes users and groups from the domain to the cloud.

Three authentication methods

  • PHS (Password Hash Sync) — the password hash is synced to the cloud. Simplest and most resilient: sign-in works even when the on-prem DC is down.
  • PTA (Pass-through Authentication) — the password is validated against the on-prem DC via an agent. No hash in the cloud, but it depends on on-prem availability.
  • Federation ( FS) — authentication is redirected to an on-prem AD FS server. Most flexible, but the most expensive and complex to maintain.

Device join

  • Azure Join — the device exists only in the cloud; good for remote staff.
  • Hybrid Azure Join — the device is domain-joined and cloud-registered; gives SSO to both worlds.
  • Entra Registered — a personal (BYOD) device with limited access.
# Device connection status to cloud and domain
dsregcmd /status

# Entra Connect synchronization check (on synchronization server)
Get-ADSyncScheduler
Start-ADSyncSyncCycle -PolicyType Delta
powershell

On-prem AD DS with Kerberos, LDAP and GPO on the left, Entra ID with OAuth2, OIDC and SAML on the right. Between them the Entra Connect or Cloud Sync server — a Tier 0 asset because it holds DCSync-level rights. Below, three authentication models: PHS syncs the password hash so the cloud verifies; PTA has an agent forward verification to an on-prem DC; ADFS federates through your own token server and carries the Golden SAML risk. Bottom line: Hybrid Join means domain joined for GPO plus Entra joined for cloud SSO.

Short and clear

  • AD DS speaks Kerberos/LDAP inside the network; Entra ID speaks OAuth2/OIDC/SAML over the Internet.
  • Entra Connect is the bridge — which makes it a Tier 0 asset with DCSync-level rights.
  • PHS is simplest and most resilient, PTA verifies against an on-prem DC, ADFS is the most complex and exposed to Golden SAML.
  • Hybrid Join = GPO from the domain plus SSO to cloud apps.

Real-life exampleA domain-joined employee opens Teams from home with no VPN: the token comes from Entra ID, while group policy still arrives from the DC when on the network.

Check yourself

Which authentication method keeps working when the on-prem domain controller is down?

Which command shows the device's domain and cloud registration state?

Was this page helpful?