Fix Microsoft 365 Access After Active Directory Password Expires
Question details
Users in a hybrid Microsoft Entra ID environment can still log in to Microsoft 365 despite their on-premises Active Directory password being expired.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Troubleshooting user authentication in a hybrid Active Directory and Microsoft Entra ID environment.
- Observed behavior
- Cloud access to Microsoft 365 remains active because cloud passwords default to never expire under certain synchronization settings, overriding the expired on-premises status.
Ensure you have Microsoft Entra ID Global Administrator or Security Administrator permissions to review authentication methods and access sign-in logs.
Verify Authentication Methods and Enforce Expiration Policies
Check if your tenant uses Password Hash Synchronization (PHS) or Pass-through Authentication (PTA) to resolve the expiration bypass.
In a hybrid environment, Password Hash Synchronization (PHS) sets cloud passwords to 'Never Expire' by default. If you use PHS, the expired on-premises Active Directory password won't block Microsoft 365 access. Pass-through Authentication (PTA) validates directly against AD, so if access continues under PTA, you may have agent health or sync issues.
Log in to the Microsoft Entra admin center, navigate to 'Hybrid management' > 'Microsoft Entra Connect', and check whether Password Hash Synchronization or Pass-through Authentication is enabled.
Go to 'Identity' > 'Users' > 'Sign-in logs' to verify how the affected user is being authenticated.
If using PTA, verify that your Pass-through Authentication agents are showing as 'Active' and healthy in the Entra Connect settings.
Open 'Active Directory Users and Computers' on your local server, locate the user, and mandate a password reset on their next logon.
Configure a Conditional Access policy in Entra ID to require Multifactor Authentication (MFA) or block access for risky sign-ins until the password is fixed.

Simplify Your Document Work with WPS Office
While managing hybrid Active Directory environments and Microsoft 365 policies can be complex, editing your documents shouldn't be. WPS Office provides a free, highly compatible, and lightweight alternative for your daily word processing, spreadsheet, and presentation needs.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install the Suite: Run the installer and follow the quick on-screen instructions to set up the software.
- 3. Open Office Documents: Launch WPS Office and directly open your existing Microsoft Word, Excel, or PowerPoint files to start editing immediately.

Frequently Asked Questions
Why does Password Hash Synchronization ignore my local password expiration?
When using PHS, Microsoft Entra ID defaults to setting the 'PasswordPolicies' attribute for synchronized users to 'DisablePasswordExpiration'. This allows cloud sign-ins even when the on-premises AD password has expired.
How can I block access immediately for a compromised user?
You can revoke the user's refresh tokens and block sign-in directly from the Microsoft Entra admin center under the user's profile settings, regardless of their password status.
Does Pass-through Authentication support cloud password expiration?
Since Pass-through Authentication validates the user's password directly against the on-premises Active Directory in real-time, any local password expiration policies will immediately apply to cloud sign-ins without needing additional cloud expiration rules.




