The on-premises domain controller then evaluates the request and returns a response to the connector, which in turn sends ...

The on-premises domain controller then evaluates the request and returns a response to the connector, which in turn sends it to %BRAND_AZURE_ACTIVE_DIRECTORY%. %BRAND_AZURE_ACTIVE_DIRECTORY% then evaluates the response and responds to the user as appropriate, for example by issuing a token or asking for multi-factor authentication. The diagram below shows the various steps.