Active Directory professional here. The passwords are stored in AD in a hash, yes, but tools like Mimikatz allow threat actors to get the hash out of the LSASS process on your machine and literally present the hash to login. It’s far and away the most common method to move laterally in a compromised corporate environment.
I understand hashing is not foolproof. And there are applications such as Corporate where this might be handy and needed. But this new MS feature should be an opt in feature. They are going to mandate it default across the board with no choice. In other words, they own your machine and you have no choice.