Cloud Security Stack
Architecture notes

Architecture

Hybrid identity: which authentication method survives which failure

Password hash sync, pass-through authentication and federation fail in different ways. The comparison that matters is what happens when something breaks.

11 min read · Reviewed 22 August 2026 · Architecture notes. Aligned to Microsoft's published hybrid identity guidance.

The comparison people make, and the one that matters

The usual comparison is about where the password is validated. That is accurate and it is not the deciding factor, because all three work fine on a normal Tuesday.

The deciding factor is what happens when your on-premises environment is unavailable. That is when the differences become the only thing anyone cares about.

Behaviour under failure
Password hash syncPass-through authFederation
Sign-in works if on-premises is down
Password validated on-premises
Extra servers to maintain
Supports leaked credential detection
Smart card or third-party MFA at sign-in

Password hash sync can be enabled alongside the other two as a fallback, which is the configuration most organisations should be running.

The recommendation almost nobody follows

Enable password hash synchronisation even if you use pass-through authentication or federation. It costs nothing, it does not change how anyone signs in day to day, and it means you can fail over to cloud authentication when your on-premises environment is unavailable.

Organisations that skipped this have discovered during a ransomware incident that their domain controllers were encrypted and therefore nobody could authenticate to anything, including the cloud services that were entirely unaffected.

What leaked credential detection needs

Entra ID Protection can flag accounts whose password has appeared in a known breach corpus. That check requires the password hash to be present in the cloud, which means password hash synchronisation. With pass-through authentication or federation alone, you do not get it.

That is a substantial security capability lost for an architectural reason most organisations never revisited.

The verdict

Our pick

Password hash synchronisation, with cloud authentication as the target state

It survives an on-premises outage, it enables leaked credential detection, and it removes servers you would otherwise have to patch and monitor.

Who should skip

Do not stay on federation without a specific requirement. Smart cards or a third-party MFA provider at sign-in are real reasons. Habit is not.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.