We have a domain with domain sync up to AAD, which works great, but we aren’t syncing back down from AAD to AD.
We still have some local resources we need (print servers, file shares, etc.) so I can’t go 100% AAD joined… or can I?
What’s the best way to set up new PCs knowing we have M365BP and successful one-way sync from AD to AAD? If I could have people log in with their AAD accounts (including modern auth/Windows Hello, etc.) I’d love it, as long as they could still access legacy services on-site until we resolve them.