On-prem Active Directory, over the public internet

Internet is the New LAN

Encrypted overlay, identity, and operations on infrastructure you control.

ControlIT extends the Domain Controllers you already run to remote staff and branch sites through an outbound-only encrypted fabric. Domain logon, Group Policy, file shares, RDP, and internal apps — with single sign-on and MFA on the same identity. No VPN. No Entra ID. Not one inbound port.

Zero inbound portsSame AD, same GPOsNo hybrid joinSelf-hostedNo per-user identity fee
Nothing listens on the internet

No inbound ports, no public IPs, no VPN concentrator. Endpoints dial out.

The directory stays yours

Same AD, same GPOs, same file shares. No hybrid join, no sync to a vendor cloud.

One console, self-hosted

Access, identity, and operations in one place, on infrastructure you control.

Endpoint Health
Desktop-PC-04Healthy
Laptop-MK-12Patch Pending
Server-DB-01Alert
Secure Remote Access
server-prod-01.internal
Or

Encrypted end-to-end, no VPN required

Policy Verification

Verifying device compliance...

OS patched
Antivirus active
Disk encrypted
Access granted
Before / after

Same directory. A very different perimeter.

Nothing about your Active Directory changes. What changes is how much of it is reachable from the public internet, and how many consoles it takes to run a Tuesday.

Head office LANDomain ControllerNever publishedFile shares · apps · RDPNo inbound ports · no public IPControlIT overlayEncrypted peer-to-peerOutbound only · identity-verified nodesHomeDomain logon · GPO · sharesPlantDomain logon · GPO · sharesBranchDomain logon · GPO · shares
RetiresVPN concentratorAzure AD Connect

Today

VPN, split tunnel, published RDP, directory sync, four consoles.

With ControlIT

One outbound-only overlay. The same on-prem AD. Zero inbound.

Remote users

laptop · mobile · branch

Today
  • A VPN client on every machine
  • Logon waits for the tunnel to come up
With ControlIT
  • An outbound-only agent, no client
  • Domain logon before the user signs in

Identity

where the directory lives

Today
  • Azure AD Connect syncing the directory out
  • Entra licensing and hybrid join to maintain
With ControlIT
  • Stays in the directory you already run
  • No Entra licence, no hybrid join, no sync

Internet boundary

what an attacker can see

Today
  • A VPN concentrator with a public IP
  • Exposed RDP, or a jump host in a DMZ
  • Split-tunnel routing that differs per site
  • A gateway every branch conversation hops through
With ControlIT
  • Encrypted peer-to-peer. Nothing listens
  • No public IPs and no inbound ports
  • Identity-verified nodes rather than trusted subnets
  • Direct paths, with no head-office bottleneck

Consoles

what your team logs into

Today4
  • VPN · RMM · SSO · MFA, from four vendors
With ControlIT1
  • Overlay, SSO and 2FA, RMM and remote support

Identical in both columns

On-prem Active DirectoryFile sharesRDP serversApplicationsDatabases

The directory does not move, and neither does anything behind it. That is the entire point.

Start here

Three ways in. None of them is a dashboard tour.

Pick the one that matches how far along you are. Each has a defined scope and a defined thing you walk away with.

45 minutes

AD-over-Internet Readiness Review

We go through your current remote-access and directory setup and tell you honestly whether an overlay is the right answer — including when it is not.

  • We inspect: current VPN, AD sites and subnets, DC exposure, remote logon failures, GPO drift, published RDP, identity stack
  • You get a one-page verdict: keep the VPN, go to Entra, or move to an overlay
  • No obligation, and no deck
See what the review covers
14 days

Pilot on one site or 25 endpoints

Success criteria written down before we start. If the pilot misses them, you walk — that is the point of putting them in writing.

  • Domain logon from a home or branch machine, with no VPN client
  • Group Policy applied, file shares reachable, RDP with no public port
  • MFA enforced on the same identity, and zero inbound ports opened
Read the pilot criteria
3-year view

VPN + Entra cost teardown

What remote access actually costs you over three years, built from published list prices, with the conditions stated rather than hidden.

  • VPN appliance refresh, support contract, and per-user licensing
  • Identity licensing — and an honest note on when Entra is already bundled in your M365 tier
  • Separate MFA and RMM subscriptions, plus the engineering time to run three consoles
Open the cost teardown
Endpoint Monitoring
Secure Access
Identity, SSO & MFA
Patch Management
Remote Support
Policy Enforcement
Automation
Asset Management
How ControlIT is packaged

Three SKUs. One control plane.

Start with the SKU that kills the VPN. Add identity when you are ready to stop paying a network problem with an identity licence. Hand the whole thing to our NOC if you would rather not run it yourself.

ControlIT control planeControlIT CoreRMM + overlayControlIT IdentitySSO/MFA + ADControlIT OpsManaged 24/7
The wedge

ControlIT Core

RMM + overlay

The encrypted outbound-only fabric plus full remote monitoring and management. This is the SKU that retires the VPN concentrator and the second remote-access tool in the same project.

  • Encrypted peer-to-peer overlay with NAT traversal — endpoints dial out, nothing listens
  • RDP, SSH, file shares, and internal apps with no port forward and no public IP
  • Endpoint health, OS patching, remote support, and scripted remediation across Windows and Linux
Explore ControlIT Core
Sovereignty

ControlIT Identity

SSO / MFA + AD over the internet

Your existing Domain Controllers, reachable from home, plant, and branch. Domain logon and Group Policy across the fabric, with one sign-on and a one-time code in front of every application.

  • Domain logon, Group Policy processing, and file shares for remote and branch machines
  • Single sign-on over OpenID Connect, OAuth2, and SAML 2.0, with TOTP MFA (RFC 6238) enforced at the identity layer
  • No hybrid join, no directory sync to a vendor cloud, no Azure AD licensing dependency
Explore ControlIT Identity
Managed service

ControlIT Ops

Managed 24/7

Computer Port runs the platform for you. Monitoring, patch windows, incident response, and reporting handled by the engineers who already operate this stack across multi-site Indian estates.

  • 24/7 monitoring and escalation against response targets agreed in contract
  • Patch windows, maintenance, and remediation run for you, with periodic reporting
  • Administrative audit trails and evidence packs for CERT-In, ISO, and DPDP conversations
Explore ControlIT Ops

Product of

Computer Port IT Solutions

Official Partnership

Proud Proxmox Silver Partner

Proxmox Silver Partner
Why ControlIT

Private access without the VPN tax.

ControlIT carries identity and application traffic through an encrypted overlay, so remote teams can reach internal resources while your ports stay closed.

Dashboard > Endpoints
Search...
System Health
Processor
0%
Memory
0%
Disk
0%
Network
0%
Activity
SRV-DB-01Online
WS-MK-14Patching
SRV-APP-03Online
LT-DEV-07Alert
Key outcomes

One console for access, health, patches, and support.

Package endpoint management, secure access, single sign-on, multi-factor authentication, automation, and reporting into one managed operations console for distributed infrastructure.

Remote Access Without VPN

Encrypted access to RDP, SSH, databases, and internal apps without public IPs or port forwarding

Keep Active Directory On-Prem

Authenticate against existing Active Directory groups without forced cloud sync, hybrid join, or Azure Active Directory licensing

Predictive Endpoint Health

Track CPU, RAM, disk, services, events, and custom sensors before users feel the incident

Zero Public Exposure

No exposed ports, no public IPs. Your infrastructure stays invisible

Multi-Site Operations

Manage branches, users, endpoints, and distributed teams from a single operations console

Automation That Pays Back

Restart services, clean disks, deploy software, and run maintenance from reusable scripts

Built-In SSO & MFA

One sign-on for every business application, a one-time code enforced on every login, and access granted or revoked from one admin console

Full Data Sovereignty

Runs on your own servers. No vendor lock-in, and your data never leaves your infrastructure

Platform architecture

From VPN-first to identity-first.

ControlIT combines an encrypted peer-to-peer private fabric, policy checks, endpoint telemetry, and technician actions into one managed operating layer.

Users & Devices

  • Laptops
  • Desktops
  • Mobile
  • Servers

Encrypted Private Fabric

  • Identity Verification
  • Policy Engine
  • Encrypted Tunnels
No exposed portsNo VPNNo Azure Active Directory

Internal Systems

  • File Servers
  • Databases
  • Applications
  • Admin Panels
Network · Identity · Operations

Three pillars. One controlled layer.

ControlIT unifies encrypted networking, identity, and endpoint operations into a single managed layer for distributed infrastructure: single sign-on, multi-factor authentication, patching, automation, and audit trails, hosted on infrastructure you control.

01

Network

Encrypted private overlay

  • Encrypted peer-to-peer overlay connectivity
  • No inbound ports, no public IP exposure
  • No VPN appliance dependency
02

Identity

Active Directory, SSO & MFA

  • Extends existing Active Directory, without Azure AD
  • Single sign-on over OpenID Connect, OAuth2, and SAML 2.0
  • TOTP multi-factor authentication and role-based access
03

Operations

Endpoint management

  • Endpoint health, patching, and remote support
  • Automation and policy enforcement
  • Audit trails and operational reporting

Secure Private Network

Encrypted peer-to-peer connectivity with NAT traversal, device identity verification, and no inbound ports.

Active Directory
SSO
MFA
Access Granted

On-Prem Active Directory Authentication

Remote users authenticate against existing Active Directory with no forced cloud sync, while role and group policies preserve control.

One
login
Web apps
SaaS
Internal apps

Single Sign-On for Cloud & Internal Apps

People sign in once and move between applications without logging in again. Because it speaks OpenID Connect and SAML, adding an application is a configuration step, not a rebuild.

481207
Authenticator appSecurity keyOne-time code
Second factor verified

Multi-Factor Authentication Built In

A stolen password cannot open the door on its own. ControlIT asks for a TOTP one-time code (RFC 6238) from any standard authenticator app, enforced in front of every application.

CPU
Memory
Disk
Services
Events
Score0/100

Endpoint Health & Remediation

CPU, RAM, disk, SMART, service, process, URL, and event sensors with health dashboards and automated fixes.

Patch & Software Management

OS patching for Windows and Linux, scheduled updates, bulk deployment, and software inventory tracking.

14:32:01User login: admin@corp
14:32:18Policy check: passed
14:33:05Report generated: Q1
Compliance Ready

Audit & Compliance

Administrative audit trails, session logging, configuration change tracking, and CERT-In-aligned reporting support.

Why switch

ControlIT vs. the traditional approach.

Remote AccessTraditionalVPNControlITDirect secure access, no VPN
IdentityTraditionalAzure Active Directory (cloud, paid)ControlITOn-prem Active Directory, no sync, no cost
SSO & MFATraditionalSeparate identity / MFA vendorControlITBuilt-in single sign-on and MFA
SecurityTraditionalExposed infrastructureControlITZero public exposure
Remote ManagementTraditionalMultiple toolsControlITUnified RMM platform
Application AccessTraditionalPort forwarding / VPNControlITEncrypted overlay tunneling
Data SovereigntyTraditionalVendor cloudControlITRuns on your own servers
PerformanceTraditionalGateway bottlenecksControlITDirect peer-to-peer connectivity
Managed OperationsTraditionalMultiple platformsControlITSingle operations console
Architecture

How ControlIT fits your infrastructure.

Endpoints, the ControlIT control plane, and your existing systems, connected through one encrypted, outbound-only layer. No VPN, no public exposure.

Endpoints & Admins

Client side

ControlIT Agent

Runs on every device. Outbound only, with no inbound ports and no public IPs.

Remote Users & Branch Sites

Distributed teams reach internal resources without a VPN appliance.

Admin Dashboard

Policy, patching, remote support, and reports from one console.

Encrypted Overlay · Outbound Only

ControlIT Control Plane

SaaS or on your own servers

ControlIT IAM

Single sign-on over OpenID Connect, OAuth2 and SAML 2.0, TOTP multi-factor authentication, and per-application access by group.

ControlIT Overlay Network

Encrypted overlay to internal apps and infrastructure, with no VPN and no public exposure.

ControlIT RMM

Endpoint health monitoring, patching, automation, and policy enforcement.

Audit & Reporting

Administrative audit trails, session logging, and operational reports.

Extends Existing AD

Existing Infrastructure

ControlIT extends, it does not replace

Active Directory & DNS

Authenticate against existing AD, without Azure AD or forced cloud sync.

File & Print Servers

Reach internal file shares over the encrypted overlay.

Internal Apps & Databases

Private application access without port forwarding.

All endpoint traffic is outbound only, with zero inbound ports and no public IP exposure. Same feature set whether ControlIT runs as SaaS or on your own infrastructure.

Product Resources

Understand The Architecture Before You Deploy.

Download the ControlIT brochure or review the secure access architecture built for Active Directory, private connectivity, endpoint operations, and zero public exposure.

Product Brochure

ControlIT Brochure

A concise PDF overview for IT heads, infrastructure teams, and business teams evaluating VPN alternatives, Active Directory-friendly access, endpoint monitoring, and managed operations.

Expansion bundles

Core first. Security and workflows when needed.

The three SKUs cover day-to-day operations. These bundles attach on top when you carry regulated risk or heavy document workflows.

Add-on

Threat Detection & Security Monitoring (SIEM / XDR)

Advanced security monitoring with intrusion detection, log analysis, vulnerability scanning, and support for CERT-In mandatory incident reporting.

Add-on

Compliance Document Management

Centralised document repository with OCR, full-text search, and tagging for IT compliance records and audit documentation.

Built for scale

Start with one site. Roll out across the estate.

Pilot ControlIT on a single office or 25 endpoints, prove the success criteria in writing, then extend the same policies, identities, and console to every site you run.

  • Endpoint Monitoring & Health
  • Remote Management & Shell Access
  • Secure Application Tunneling
  • Identity & Active Directory
  • Single Sign-On & Multi-Factor Authentication
  • Automation & Script Library
  • Multi-Site Managed Operations

Client proof

Trusted by infrastructure teams.

Real feedback from Computer Port customers whose environments rely on secure access, authentication, and post-implementation support.

Computer Port delivered exactly the right solution for our requirements - and at a cost that made sense. Their expertise during the consulting stage and the quality of post-implementation support genuinely impressed me.

Clynton Almeida

CIO, Redington India

Computer Port's Linux-based authentication system has been handling over 900 users since 2014 without a single issue. Windows desktops and laptops authenticate seamlessly.

Chevva Reddy

Head of IT, Thirumala Milk

We engaged Computer Port for two-factor authentication and were impressed by the depth of expertise their team brought to the engagement. A smooth, well-executed implementation from start to finish.

K. Saritha

Head of IT, Toshiba T&D India

Book a 45-minute AD-over-Internet review

One page back, not a proposal

We look at your VPN, your AD sites and subnets, what is currently published to the internet, and where identity lives. You get a one-page verdict: keep the VPN, go to Entra, or move to an overlay.

ControlIT logo with Internet is the New LAN tagline