Our organization has an on-premises Active Directory (AD) integrated with Azure AD Connect and Single Sign-On (SSO) configured, including the password write-back option. We've set a password expiration policy of 90 days at the organizational level in both Office 365 and the on-premises AD Group Policy.
However, I've observed an issue where some users, primarily working from home and not regularly connecting to the official network, are still able to access their email and log into Outlook beyond the 90-day password expiration limit. According to our configuration, they should be prompted to reset their passwords or face login restrictions upon expiration.
Could anyone help me understand the possible root cause of this behavior and suggest steps to resolve the issue?