Thanks for the post.
Did AD connect only used for passwrod has sync or ?
do you mean removing the AD connect sync completely form your infra?
what is your local AD password policy - have you set for expiration ?
also do you have password policy set in azure AD. Explain your setup please.