I'm not yet sure what is the best setup for integration Azure AD as target system.
We need hybrid users (with SSO), so AAD Connect is required anyway.
It is required as well for other purpose like device management.
Now I see the following two options…