Azure AD was the first service made available on Azure, and it is the authority service for user management in Microsoft Office 365. It is a core service, built on a global infrastructure, meant to provide a base identity management system to each organization.
What is identity management? It is a foundational system for any environment, which maintains the identity of each user object in a central location and controls access to other users, resources, and objects of that environment.
Identity management has two components—authentication and authorization, as shown in the following figure:

As shown in the following figure, your organization may want to connect its on-premises AD with Office 365:
