Said It Here

How to handle SSO and device management for local AD and M365?

Hybrid environments combining local Active Directory, Microsoft 365, and remote VPNs lack a unified way to handle credentials across separate domains. This disconnect prevents cloud-identity users from signing in to local machines and breaks centralized device management.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Setting up hybrid directory sync using tools like Entra Connect
  2. 2
    Transitioning entirely to cloud-native identity and device management with cloud kerberos trust
  3. 3
    running production and development on the same active directory and tenant

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

r/sysadmin2 people · October 2026

“How did you let cloud-identity users sign in to machines in a separate dev domain?”source ↗

joey_bane · r/sysadmin · 25 upvotes

“How to handle SSO & device management for local AD domain + M365 with FortiGate VPN remote users?”source ↗

Prudent-Big-9068 · r/sysadmin · 1 upvotes

Where this came up

People with this problem also raised