Windows domains, part 5: hybrid identity — Entra Connect, the PRT, and the seam between two worlds
Part 5from the Windows domains series · 6 parts in all
By 2022 the forest was no longer the whole story. Most enterprises run a hybrid: AD for the devices, file servers, and legacy apps; Entra ID (Azure AD, renamed 2023) for Microsoft 365, SaaS, and increasingly everything else. This part is about the seams — how accounts, passwords, and proof-of-identity flow across them.
Three ways to sync, one direction that wins
Entra Connect (née DirSync/AADSync) offers password hash sync — a synchronized hash-of-hash flows to Entra, authentication happens in the cloud; pass-through authentication — Entra validates against on-prem agents; and federation via ADFS — Entra redirects to your STS. The industry settled hard on PHS: it is the only mode whose outage story is "flip a switch to cloud auth", and it feeds Entra ID Protection's leaked-credential detection. Seamless SSO layers a Kerberos ticket trick onto PHS/P TA so browser sessions on domain-joined machines skip the password prompt.
The Primary Refresh Token: Kerberos's grandchild
Windows 10+ devices that are hybrid-joined get a PRT — a long-lived, device-bound token that proves "this user, on this device, attested by hardware" to every Microsoft and modern-auth app, refreshed silently in the background. It is conceptually the TGT's cloud descendant: issued once after strong logon (Windows Hello for Business), presented everywhere, never typed. Windows Hello and FIDO2 keys then delete the shared secret entirely — the password stops existing, so it cannot be phished, while Entra's cloud Kerberos trust makes even legacy NTLM-shaped file-share access work passwordlessly (part 6).
The wake-up calls
Hybrid also widened the attack surface, and the decade's incidents taught the lessons publicly: Zerologon (2020) turned the NTLM-era Netlogon protocol into a domain-takeover primitive until a breaking patch forced secure Netlogon; NTLM relay chains kept resurfacing in Print Spooler and PetitPotam; and print-nightmare-class bugs reminded everyone that DCs are tier-0. The modern answers are Conditional Access (identity + device + risk at every door), tiered administration, and treating NTLM as a deprecation target rather than a compatibility cushion.
# the seam, inspected from both ends
dsregcmd /status # hybrid-joined? AzureAdPrt: YES? user state at a glance
Get-MgOrganization # tenant data (Graph SDK superseded the MSOnline module)
# passwordless on-prem file access via Entra cloud Kerberos trust
Install-Module AzureADHybridAuthenticationManagement
Set-AzureADKerberosServer -Domain "maplecart.local" -CloudCredential $cred
Part 6 brings the story current: Server 2025, the official NTLM deprecation, and what "the forest" means when identity's center of gravity has moved to the cloud.