Solution
Active Directory Over The Internet, Without Azure AD
Reach your existing on-prem domain controllers from anywhere over an encrypted, outbound-only overlay. Domain logon, Group Policy, and file shares with no Azure AD licensing, no hybrid join, and no directory sync to a vendor cloud.
Why this matters
Microsoft answers remote Active Directory by moving your identity to Entra. ControlIT answers it by keeping the domain controller yours and making the internet behave like the LAN it already sits on.
- Your existing domain controllers stay exactly where they are. No new forest, no new domain, no trust relationship, and no schema change.
- Remote and branch machines reach the directory across an encrypted peer-to-peer fabric, so domain logon, Group Policy processing, and file-share access work the way they do in the office.
- Nothing is published to the internet. Endpoints establish outbound connections, so there is no inbound port, no public IP, and no domain controller sitting in a DMZ.
- No Azure AD Connect, no hybrid join, and no forced directory synchronisation. Your user objects and password hashes stay inside your estate.
- Single sign-on and TOTP multi-factor authentication run against the same directory identity, so you are not maintaining a second parallel user database.
Outcomes
Remote staff under the same directory policy as head office
No identity migration project just to enable remote work
No Entra licence line item added to enable remote AD
A smaller external attack surface than published RDP or a DMZ DC
Defensible answers for data-localisation and CERT-In questions
Related ControlIT pages
Domain join without VPNEntra ID alternativeAD readiness reviewControlIT overviewArchitectureProduct BrochureTalk to Computer Port
Published by Computer Port IT Solutions. This page is part of the ControlIT product knowledge base for search engines, AI crawlers, and IT teams evaluating secure endpoint operations.