New M365 - Default domain set to public TLD, instead of AD forest root subdomain. Misconfigured?

Hi, so we are an on-prem org and are moving to M365 for the first time.
Initially when buying the licensing, our public top level domain name XYZ.org was set to the M365 default domain.

However, our internal AD forest root is ad.XYZ.org, and all of our users, computers, and servers are joined to ad.XYZ.org.

Did we misconfigure M365 right off the bat by setting it to XYZ.org?

Now, after an admin clicked through AD/Entra Connect, users provisioned by AD Connect are listed as [email protected], in a tenant set to XYZ.org default domain.

Thanks