Concept and mechanism
Synchronization and authentication are related but different decisions. Synchronization creates or updates identity representations; authentication validates sign-in. Password hash synchronization enables Entra ID validation using synchronized material without storing plaintext passwords. A local change must reach cloud before the new value can be used on that path. Pass-through authentication uses agents validating against on-premises AD and depends on that path. Federation hands validation to a trusted system. Compare availability, required policy, and operational capability. Preparing PHS as a PTA alternative does not enable automatic failover: the runbook needs a controlled method switch and validation.
Guided application
In a fictional acquisition, disconnected forests can motivate Cloud Sync evaluation. Documentation includes this scenario with agents and cloud orchestration; compare features and limitations before replacing the existing design. Do not infer full Connect Sync equivalence simply because both synchronize identities. For partners, separate the account-managing tenant, resource-hosting tenant, and applicable inbound and outbound rules. Cross-tenant access controls collaboration and permits trust in selected claims such as MFA. That trust does not automatically assign application roles. At handover, provide a map of tenants, owners, dependencies, trust configuration, and recovery actions. Exercise local failure and partner authorization failure as separate situations so the team does not try fixing connectivity by adding privileges.
PHS prepared, PTA unavailable, and method unchanged: the team still needs to perform the authorized switch.
Common pitfalls
Synchronization as authentication; prepared backup as activated backup; partner MFA as authorization; agents as complete parity.
Related topics: Tenant, scope, and objects · Methods and emergency access · Conditional Access and risk
Document who validates, dependencies, and recovery for each access path.
Reference: Hybrid authentication choices · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately