Azure AD Connect is a free Microsoft tool used for synchronizing on-prem Active Directory infrastructures with Microsoft’s cloud-based Azure Active Directory. The previously available software “Dirsync” is no longer supported.
Azure AD Connect automatically copies on-prem Active Directory users and groups to Azure Active Directory. You should only create and edit new users and groups in Azure AD if you intend for them to remain “online only” (which means these users have an Azure AD account but do not have a user account in on-prem Active Directory). There are also advanced settings available that allow you to synchronize multiple local domains and forests with Azure AD.
Modes of Authentication With Azure AD Connect:
- Password hash synchronization: the local Active Directory password is synchronized to Azure AD in hash format (difficult to convert to plain text).
- Pass-through authentication
- Active Directory Federation Services