Hybrid joined devices are technically devices that are joined to Windows Server AD. So authentication of the device and the user will go to Windows Server AD.
Hybrid join is added on top, so that Azure AD “knows” something about the device.
On Azure AD joined devices, all interaction goes to Azure AD. Only if an application explicitely does Kerberos, a TGT is pulled.
I would say Hybrid join quite a big step backward.
Any chance to change that applications?
Greetings,
MrAzureAD