
This would not be a password reset, it would just be someone who's magically authenticated. So, let's talk about the second method for hybrid, which is pass-through authentication. And in that case, the user goes directly to Entra ID. Entra ID asks who they are, and they provide their username and password, and that is then sent to a queue, which is then pulled by a AD Connect server, which lies on prem. And when they got the new thing, they will just validate that, and eventually, if it's yeah, successful, it will send a boolean, basically, which is yes or no.