Hi @simon vdp ,
My understanding is if your organization uses a third-party federation solution, you can configure SSO for your on-premises Active Directory users with Microsoft Online services, such as Microsoft 365, provided the third-party federation solution is compatible with Entra ID/Azure AD.
For questions regarding compatibility, you would need to contact your identity provider. There is a list of identity providers who have previously been tested for compatibility with Entra ID (by Microsoft) here: Entra ID identity provider compatibility docs.
You would need to define both the tenants to which IDP will be connected and the domain you want to federate from the tenant. So, users belonging to non-federated domain will be using Entra ID/Azure AD as IDP.
What you are describing should be possible if the IdPs are compatible with Entra ID/Azure.
https://learn.microsoft.com/en-us/entra/external-id/direct-federation#frequently-asked-questions