Integrating Azure AD with On-premises AD, but without syncing users to Azure AD

Mina Gobrial 0 Reputation points
2024-01-11T20:56:36.0233333+00:00

We are looking to integrate Azure AD with On-premises AD, but without syncing users to Azure AD to save us the cost of having them stored on Azure with the licenses required. We need eventually to authenticate users through the on-premises AD and to enable them to log in to Azure accounts using their on-premises AD.

What is the recommended solution for that?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,041 questions
Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,213 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,004 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Thameur-BOURBITA 32,606 Reputation points
    2024-01-11T21:16:12.9833333+00:00

    Hi @Mina Gobrial

    If you have a hybrid environment , It's not good idea to not sync AD user to Entra ID. Without synchronization , user cannot use his AD account to authenticate in Azure.

    You can enable synchronization without affecting a licence for synced user because the synchronization through Entra connect server doesn't affect automatically a licence to a synced user. When the synchronization is enable between AD on-premise and Entra ID through Entra connect server , user will be able to use his AD account to access on Azure by enabling one of SSO method:

    Fedaration service ( need to install a additional server) Synchronisation of hash password Pass-through authentication

    To get more details I invite you to read these articles:

    Azure Hybrid Identity Authentication Methods

    What is hybrid identity with Microsoft Entra ID?


    Please don't forget to accept helpful answer

    0 comments No comments