On-premises Active Directory
A traditional local Active Directory domain, running on a server in your practice, remains a strong fit for many sites — particularly where a local server is already hosting your digital imaging and DPMS. It gives you centralised user accounts, group policy to lock down and standardise every workstation, shared drives with proper permissions, and fast authentication on site that does not depend on your internet connection. We deploy, secure and maintain local AD, including domain controllers, group policy and DNS.
Hybrid identity — AD joined to Microsoft Entra ID
For most practices already using Microsoft 365, the strongest option is hybrid: your on-premises Active Directory synchronised to Microsoft Entra ID (formerly Azure AD). Staff use one set of credentials for their local PC, their email and their cloud apps, with single sign-on across all of them. You keep the on-site control and speed of local AD, while gaining cloud security features — multi-factor authentication, conditional access and self-service password reset — and the ability to manage and secure devices centrally. We handle the sync, the configuration and the security hardening end to end.
Cloud-only — Microsoft Entra ID
Newer and increasingly common, a cloud-only model does away with the local server entirely: identity lives in Microsoft Entra ID, and devices are joined and managed directly from the cloud with Intune. This suits squat practices, sites with no need for a local server, and groups standardising on a modern, server-light estate. Staff sign in to their device and every cloud service with one secure identity, and you manage everything — users, devices, security policy — from anywhere, with no domain controller to maintain.
Which model is right for your practice?
The right answer depends on what clinical software you run, whether you need a local server, how many sites you operate, and where you want to be in a few years. On-premises is robust and fast on site; hybrid is the pragmatic sweet spot for most established practices on Microsoft 365; cloud-only is the cleanest option for new or server-light sites. As part of our network audit we will assess where you are now and recommend the model — and the migration path — that fits.
Security built in
Whichever model you choose, we apply the same security standards: multi-factor authentication, conditional access policies that restrict logins to trusted devices and locations, least-privilege permissions, and single sign-on so staff have fewer passwords to manage and you have fewer ways in for an attacker. Book a call to review your identity setup.