Enable the Password sync using the AADConnect Agent Server. Configure hybrid Azure AD join by using Azure AD Connect for a managed domain: Start Azure AD Connect, and then select Configure. Sign-in auditing and immediate account disable are not available for password synchronized users, because this kind of reporting is not available in the cloud and password synchronized users are disabled only when the account synchronization occurs each three hours. You can use ADFS, Azure AD Connect Password Sync from your on-premise accounts or just assign passwords to your Azure account. Because of this, we recommend configuring synchronized identity first so that you can get started with Office 365 quickly and then adding federated identity later. For more information about domain cutover, see Migrate from federation to password hash synchronization and Migrate from federation to pass-through authentication. The configured domain can then be used when you configure AuthPoint. While users are in Staged Rollout with PHS, changing passwords might take up to 2 minutes to take effect due to sync time. Users who've been targeted for Staged Rollout are not redirected to your federated login page. The various settings configured on the trust by Azure AD Connect. How does Azure AD default password policy take effect and works in Azure environment? Microsoft recommends using Azure AD connect for managing your Azure AD trust. So, we'll discuss that here. Applications or cloud services that use legacy authentication will fall back to federated authentication flows. Self-Managed Domain A self-managed domain is an AD DS environment that you can create in the cloud using the traditional tools. On the intranet, go to the Apps page in a private browser session, and then enter the UserPrincipalName (UPN) of the user account that's selected for Staged Rollout. Admins can roll out cloud authentication by using security groups. Client Access Policy is a part of AD FS that enables limiting user sign-in access based on whether the user is inside or outside of your company network, or whether they are in a designated Active Directory group and outside of your company network. To use the Staged Rollout feature, you need to be a Hybrid Identity Administrator on your tenant. Identify a server that'srunning Windows Server 2012 R2 or laterwhere you want the pass-through authentication agent to run. To learn how to set 'EnforceCloudPasswordPolicyForPasswordSyncedUsers' see Password expiration policy. Ie: Get-MsolDomain -Domainname us.bkraljr.info. In this case all user authentication is happen on-premises. The guidance above for choosing an identity model that fits your needs includes consideration of all of these improvements, but bear in mind that not everyone you talk to will have read about them yet. Require client sign-in restrictions by network location or work hours. The first one is converting a managed domain to a federated domain. The file name is in the following format AadTrust--