Azure AD / Entra ID
Last updated
Last updated
An on-premises AD can be integrated with Azure AD using Azure AD Connect with the following methods:
Password Hash Sync (PHS)
Pass-Through Authentication (PTA)
Federation
Azure AD Connect is installed on-premises and has a high privilege account both in on AD and Azure AD
Password Hash Sync (PHS) shares users and their password hashes from on-premises AD to Azure AD.
A new users MSOL_ is created which has Synchronization rights (DCSync) on the domain
MSOL (Microsoft Online Services) accountObtain Microsoft 365 access tokens using on-premises Active Directory Kerberos tickets for organizations with Seamless SSO (Desktop SSO) enabled
Leverage device-stored keys (Device key, Transport key etc..) to authenticate to Microsoft Entra ID.