Is your question whether you can allow a hybrid user to log into an Azure VM using their AAD credentials if the user is blocked from Azure AD?
I believe your best bet would be to use local admin accounts in that scenario. https://techcommunity.microsoft.com/t5/azure-active-directory-identity/azure-ad-authentication-to-windows-vms-in-azure-now-in-public/ba-p/827840