Architecture
Hybrid identity: which authentication method survives which failure
Password hash sync, pass-through authentication and federation fail in different ways. The comparison that matters is what happens when something breaks.
The comparison people make, and the one that matters
The usual comparison is about where the password is validated. That is accurate and it is not the deciding factor, because all three work fine on a normal Tuesday.
The deciding factor is what happens when your on-premises environment is unavailable. That is when the differences become the only thing anyone cares about.
| Password hash sync | Pass-through auth | Federation | |
|---|---|---|---|
| Sign-in works if on-premises is down | |||
| Password validated on-premises | |||
| Extra servers to maintain | |||
| Supports leaked credential detection | |||
| Smart card or third-party MFA at sign-in |
Password hash sync can be enabled alongside the other two as a fallback, which is the configuration most organisations should be running.
The recommendation almost nobody follows
Enable password hash synchronisation even if you use pass-through authentication or federation. It costs nothing, it does not change how anyone signs in day to day, and it means you can fail over to cloud authentication when your on-premises environment is unavailable.
Organisations that skipped this have discovered during a ransomware incident that their domain controllers were encrypted and therefore nobody could authenticate to anything, including the cloud services that were entirely unaffected.
What leaked credential detection needs
Entra ID Protection can flag accounts whose password has appeared in a known breach corpus. That check requires the password hash to be present in the cloud, which means password hash synchronisation. With pass-through authentication or federation alone, you do not get it.
That is a substantial security capability lost for an architectural reason most organisations never revisited.
The verdict
Password hash synchronisation, with cloud authentication as the target state
It survives an on-premises outage, it enables leaked credential detection, and it removes servers you would otherwise have to patch and monitor.
Do not stay on federation without a specific requirement. Smart cards or a third-party MFA provider at sign-in are real reasons. Habit is not.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.