HI Andre,
It is bit different scenario as the source is not available and there is no way you can sync back from AAD to onpremise and match the objects in reverse, so the I will suggest you read this article as the soft match and hard match is the possibilty by using UPN or one of the attributes once you create the Onprem AD. https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/how-to-connect-install-existing-tenant
Check this specific with UPN matching and this will help you - https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/use-upn-matching-identity-sync
Hope this helps.
JS
==
Please accept as answer and do a Thumbs-up to upvote this response if you are satisfied with the community help. Your upvote will be beneficial for the community users facing similar issues