FIRST, WHAT IS A DOMAIN CONTROLLER?

A domain controller is the server that runs your Active Directory, this is the system that decides who can sign in to your computers, what they're allowed to open, and how how every machine in the business behaves. Think of it as the front desk and keyholder to your entire network. It's been around since 2000, which is exactly why people assume it must be obsolete. It isn't, and it's still doing jobs nothing else does as well. What has dated is where it loves: it no longer needs a dusty server room to sit in. Ours run in Clear Skies, our UK Hosted Private Cloud environment.

"BUT EVERYTHING'S IN THE CLOUD NOW"

Some of it is. Your email, Teams and SharePoint almost certainly live in Microsoft 365, signed into through Entra ID — Microsoft's cloud identity service. That part of the story is true.But walk around most UK businesses and you'll find the rest of the story: file servers, label printers, door entry systems, CAD workstations, finance packages, manufacturing software. These systems authenticate against Active Directory. They neither know nor care that Entra ID exists — and replacing them all just to retire a directory is spending a lot of money to solve a problem you don't have. The better question isn't whether to keep your domain controller. It's where it should live — and the answer is no longer a cupboard in the office. Hosted in Clear Skies, it does the same job from a UK data centre: patched, backed up, monitored, and reachable from every site over a secure connection.

THE SECURITY CASE FOR KEEPING IT

This is the part that surprises people: a well-run domain controller is a security asset, not a liability.
  • One place to set the rules. Group Policy pushes your security standards to every PC automatically — screen locks, blocked software, USB restrictions, password rules. No chasing individual machines.
  • Control that stays yours. Your identity system enforces your rules, held in a UK data centre you can point to — not dissolved into a global platform's defaults.
  • Instant off-boarding, everywhere. Disable one account and a leaver loses access to every PC, share and application at once — including the systems cloud identity can't see.
  • Evidence for insurers and auditors. Cyber-insurance questionnaires still ask how you control devices and access. "Group Policy, centrally enforced, hosted in a UK data centre" is an answer they recognise and like.
The honest caveat: an unpatched, forgotten domain controller is a genuine risk — it's a high-value target. That's exactly why ours live in Clear Skies, where patching, backups and monitoring are our job, not an afterthought.

THE BEST ANSWER IS USUALLY BOTH

Here's the bit the "AD is dead" headlines skip: Microsoft's own recommended setup for most established businesses is hybrid. A tool called Entra Connect syncs your directory with Microsoft 365, so each person has one identity and one password for everything — email, Teams, and the finance system alike.

Each side then does what it's best at. Entra ID handles sign-in from anywhere, multi-factor authentication and modern apps. Your Clear Skies–hosted domain controller handles the rest: PC sign-in, file shares, printers, older applications and device policy — without you owning, powering or patching a single box. You get the flexibility of cloud without abandoning the systems your business actually runs on.

THE SECURITY CASE FOR KEEPING IT

This is the part that surprises people: a well-run domain controller is a security asset, not a liability.
  • One place to set the rules. Group Policy pushes your security standards to every PC automatically — screen locks, blocked software, USB restrictions, password rules. No chasing individual machines.
  • Control that stays yours. Your identity system enforces your rules, held in a UK data centre you can point to — not dissolved into a global platform's defaults.
  • Instant off-boarding, everywhere. Disable one account and a leaver loses access to every PC, share and application at once — including the systems cloud identity can't see.
  • Evidence for insurers and auditors. Cyber-insurance questionnaires still ask how you control devices and access. "Group Policy, centrally enforced, hosted in a UK data centre" is an answer they recognise and like.
The honest caveat: an unpatched, forgotten domain controller is a genuine risk — it's a high-value target. That's exactly why ours live in Clear Skies, where patching, backups and monitoring are our job, not an afterthought.

WHAT WE'D DO FIRST

Before making any decision about your domain controller, you need to know what it's actually doing. Our AD health check gives you exactly that:

  1. Map everything that depends on Active Directory today.
  2. Check its health — patching, backups, replication, security posture.
  3. Recommend, in plain English: move it into Clear Skies, hybridise with Microsoft 365, or plan retirement — with evidence either way.

WHAT WE'D DO FIRST

A fixed scope review, a plain english report and a plan you can act on. Let's make IT happen.

Book an AD Health Check

Company No: 06687050
VAT No: 940180645
©2025 Addooco IT Limited

Addooco IT Limited
Dundee House, Millennium Way
Chesterfield, Derbyshire, S41 8ND

Addooco IT Limited
Dundee House, Millennium Way
Chesterfield, Derbyshire, S41 8ND

Call: +44 1246 887887
Privacy Policy | Terms

Addooco IT Limited
Dundee House, Millennium Way
Chesterfield, Derbyshire, S41 8ND

Call: +44 1246 887887
Privacy Policy | Terms

Privacy Preference Center