I've been told 2 way sync of AD connect is not possible which means it probably doesn't do anything of what I need it to do. How do modern configurations connect AD DS + Azure AD (Office 365 E3) services if AD connect cannot do a 2 way sync?
My goal is to get Windows Hello for Windows 10/11 login connected to Azure AD and the local DS so that users login to a profile already connected to their Azure AD office.com work/school account. While also being able to configure group policy.
Is this possible? It seems like a really basic configuration. I was looking at AD FS but I'm not sure that's the right path either.
How do my users login to a domain and then not have to sign in again to their Microsoft Office 365 accounts in Windows 10/11 account settings?
I appreciate your time, thank you.