How to handle SSO and device management for local AD and M365?
Hybrid environments combining local Active Directory, Microsoft 365, and remote VPNs lack a unified way to handle credentials across separate domains. This disconnect prevents cloud-identity users from signing in to local machines and breaks centralized device management.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Setting up hybrid directory sync using tools like Entra Connect
- 2Transitioning entirely to cloud-native identity and device management with cloud kerberos trust
- 3running production and development on the same active directory and tenant
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
r/sysadmin2 people · October 2026
Where this came up
People with this problem also raised
- 2Why do privileged Salesforce users have to create separate passkeys?
- 3How do you manage accounts and passwords that don't use SSO?
- 2How to manage on-premises servers without an Active Directory domain
- 8How to migrate company email from Google Workspace to Microsoft 365
- 3Why do CRM apps share my customer data with other companies?
- 3How to backup Microsoft 365 tenant configurations