logo
search
Sign-in & Login Problems

Fix Microsoft 365 Access After Active Directory Password Expires

Huda QurayshiHuda Qurayshi Sep 28, 2026 869 views

Question details

Users in a hybrid Microsoft Entra ID environment can still log in to Microsoft 365 despite their on-premises Active Directory password being expired.

Why Microsoft 365 Access Continues After an Active Directory Password Expires
Product
Microsoft 365
Device & OS
not provided
Scenario
Troubleshooting user authentication in a hybrid Active Directory and Microsoft Entra ID environment.
Observed behavior
Cloud access to Microsoft 365 remains active because cloud passwords default to never expire under certain synchronization settings, overriding the expired on-premises status.
Before you start

Ensure you have Microsoft Entra ID Global Administrator or Security Administrator permissions to review authentication methods and access sign-in logs.

Solution 1Recommended

Verify Authentication Methods and Enforce Expiration Policies

Check if your tenant uses Password Hash Synchronization (PHS) or Pass-through Authentication (PTA) to resolve the expiration bypass.

In a hybrid environment, Password Hash Synchronization (PHS) sets cloud passwords to 'Never Expire' by default. If you use PHS, the expired on-premises Active Directory password won't block Microsoft 365 access. Pass-through Authentication (PTA) validates directly against AD, so if access continues under PTA, you may have agent health or sync issues.

1
Review Authentication Configuration

Log in to the Microsoft Entra admin center, navigate to 'Hybrid management' > 'Microsoft Entra Connect', and check whether Password Hash Synchronization or Pass-through Authentication is enabled.

2
Analyze Sign-in Logs

Go to 'Identity' > 'Users' > 'Sign-in logs' to verify how the affected user is being authenticated.

3
Check PTA Agent Health

If using PTA, verify that your Pass-through Authentication agents are showing as 'Active' and healthy in the Entra Connect settings.

4
Force an On-Premises Password Reset

Open 'Active Directory Users and Computers' on your local server, locate the user, and mandate a password reset on their next logon.

5
Enable Conditional Access

Configure a Conditional Access policy in Entra ID to require Multifactor Authentication (MFA) or block access for risky sign-ins until the password is fixed.

Verify Authentication Methods and Enforce Expiration Policies
EnforceCloudPasswordPolicyForPasswordSyncedUsers: If you want to keep PHS but enforce local expiration, you can enable the EnforceCloudPasswordPolicyForPasswordSyncedUsers feature via PowerShell.
Free Microsoft Office alternative

Simplify Your Document Work with WPS Office

While managing hybrid Active Directory environments and Microsoft 365 policies can be complex, editing your documents shouldn't be. WPS Office provides a free, highly compatible, and lightweight alternative for your daily word processing, spreadsheet, and presentation needs.

  1. 1. Download WPS Office: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Install the Suite: Run the installer and follow the quick on-screen instructions to set up the software.
  3. 3. Open Office Documents: Launch WPS Office and directly open your existing Microsoft Word, Excel, or PowerPoint files to start editing immediately.
Free to download and use with a highly intuitive, familiar interface.Excellent compatibility with Microsoft Office formats including DOCX, XLSX, and PPTX.Lightweight software that runs smoothly on older or low-spec devices.No complicated cloud sync or Active Directory setup required for local offline editing.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Password Hash Synchronization ignore my local password expiration?

When using PHS, Microsoft Entra ID defaults to setting the 'PasswordPolicies' attribute for synchronized users to 'DisablePasswordExpiration'. This allows cloud sign-ins even when the on-premises AD password has expired.

How can I block access immediately for a compromised user?

You can revoke the user's refresh tokens and block sign-in directly from the Microsoft Entra admin center under the user's profile settings, regardless of their password status.

Does Pass-through Authentication support cloud password expiration?

Since Pass-through Authentication validates the user's password directly against the on-premises Active Directory in real-time, any local password expiration policies will immediately apply to cloud sign-ins without needing additional cloud expiration rules.