Does both (Onprim ad + Azure AD ) login work simulationly?

%3CLINGO-SUB%20id%3D%22lingo-sub-1341815%22%20slang%3D%22en-US%22%3EDoes%20both%20(Onprim%20ad%20%2B%20Azure%20AD%20)%20login%20work%20simulationly%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1341815%22%20slang%3D%22en-US%22%3EI%20need%20information%20if%20it's%20possible%20to%20work%20simultaneity%20on-premises%20Active%20Directory%20and%20Hybrid%20Azure%20AD%20Authentication%20framework%20for%20the%20endpoint%20(%20Workstation%20login)%20%3F%3CBR%20%2F%3E%3CBR%20%2F%3EMy%20requirement%20is%20to%20achieve%20%2C%20When%20System%2FLaptop%20is%20trying%20to%20login%20for%20corporate%20network%20then%20it%20should%20use%20local%20AD%20DC%20authentication%20while%20when%20same%20device%20try%20to%20login%20from%20outside%20network%20then%20it%20should%20authenticate%20with%20hybrid%20Azure%20AD.%3CBR%20%2F%3E%3CBR%20%2F%3EWhat%20are%20the%20Authentication%20framework%20for%20the%20endpoint%20will%20work%20e.g.%20Hybrid%20AD%20with%20Azure%20AD%20with%20Duo%20%2F%20MFA%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1341815%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1342393%22%20slang%3D%22en-US%22%3ERe%3A%20Does%20both%20(Onprim%20ad%20%2B%20Azure%20AD%20)%20login%20work%20simulationly%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1342393%22%20slang%3D%22en-US%22%3EHi%20KRISAZUREAD%2C%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20Hybrid%20AAD%2C%20you%20always%20authenticate%20to%20OnPrem%20AD%2C%20when%20you%E2%80%99re%20in%20the%20network%20you%20authenticate%20directly%20to%20one%20of%20the%20DCs%20(whether%20physical%2F%20VM%20or%20IaaS).%3CBR%20%2F%3EWhen%20you%20authenticate%20from%20Outside%2C%20the%20device%20uses%20the%20last%20locally%20cached%20username%20and%20password%2C%20so%20in%20case%20you%20changed%20the%20password%20from%20AD%20and%20the%20device%20out%20of%20the%20network%2C%20you%20need%20to%20connect%20p2s%20vpn%20to%20update%20the%20pc%20with%20new%20password.%20If%20you%20want%20to%20have%20flexibility%20to%20login%20from%20anywhere%20without%20vpn%2C%20use%20AAD%20(Cloud%20only%20environment).%3CBR%20%2F%3E%3CBR%20%2F%3EFor%20MFA%20with%20DUO%2C%20it%20works%20with%20AAD%20or%20Hybrid%2C%20what%20do%20you%20want%20to%20use%20it%20for%3F%202FA%20for%20P2S%20vpn%20or%20regular%20login%20to%20Windows%20PCs%3F%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20this%20helps!%3CBR%20%2F%3EMoe%3C%2FLINGO-BODY%3E
Occasional Visitor
I need information if it's possible to work simultaneity on-premises Active Directory and Hybrid Azure AD Authentication framework for the endpoint ( Workstation login) ?

My requirement is to achieve , When System/Laptop is trying to login for corporate network then it should use local AD DC authentication while when same device try to login from outside network then it should authenticate with hybrid Azure AD.

What are the Authentication framework for the endpoint will work e.g. Hybrid AD with Azure AD with Duo / MFA ?
1 Reply
Hi KRISAZUREAD,

In Hybrid AAD, you always authenticate to OnPrem AD, when you’re in the network you authenticate directly to one of the DCs (whether physical/ VM or IaaS).
When you authenticate from Outside, the device uses the last locally cached username and password, so in case you changed the password from AD and the device out of the network, you need to connect p2s vpn to update the pc with new password. If you want to have flexibility to login from anywhere without vpn, use AAD (Cloud only environment).

For MFA with DUO, it works with AAD or Hybrid, what do you want to use it for? 2FA for P2S vpn or regular login to Windows PCs?

Hope this helps!
Moe