A cloud-based identity and access management service for securing user authentication and resource access
Sync is one-way only, from on-premises AD to Azure AD, thus the on-prem accounts will be "source of authority". Syncing doesnt depend on any license, if you want to limit which accounts sync to Azure AD use filtering as detailed here: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering