User validation based on the membership of Azure AD/Entra ID groups is now supported.
It’s necessary to configure Azure AD Integration to use Azure AD validation.
Afterwards, you can easily add groups by selecting them from a drop-down list.
User logon credentials are automatically passed through to Azure AD, when an endpoint is joined to Azure AD only.
When an endpoint is hybrid-joined, validation is performed against on-prem AD and then Azure AD. If the validation against the on-prem AD fails and the corresponding UPN doesn’t exist in Azure AD, the user is prompted to enter their Azure AD credentials.