Hybrid Identity Authentication & Entra Connect Hybrid identity model & directory synchronisation is the most common for enterprise users Directory synchronisation allows updates to AD DS to synchronise with the Entra ID AD DS identities are synchronised with Microsoft 365 and users are managed on-prem Managed Authentication Password Hash Synchronisation (PHS) (Recommended) Entra ID handles authentication using a locally hashed password Password hashes are synchronised out from AD DS to Entra ID so that users have the same password Pass-Through Authentication (PTA) Entra ID sends the credentials to an on-prem software agent to be authenticated by AD DSĀ  Federated Authentication Federated Authentication - Entra ID redirects the client's authentication request to another identity provider Primarily for large enterprises with more complex requirements Users have the same password on-prem and in the cloud and do not have to sign in again to use 365 Supports additional requirements such as smartcards or third party MFA