


I want to setup a multi-tiered domain structure, begin using Privileged Access Management (PAM), and other best practices for security as recommended by Microsoft, and SANS. We'll continue to have member servers, and I assume one or two on-premise domain controllers that sync with Azure AD.

We've licensed everyone for Office 365 E5, Enterprise Mobility & Security (EMS) E5, and Windows Enterprise E5. We're about to replace our old setup of SBS server, 2nd domain controller, many member servers, and volume licensed Windows Enterprise. Here is the some background on the systems we support. If you don't feel like reading all of this, I'm considering Chromebooks for sys admin work. I'm seeking opinions of my plan to change the notebooks our IT staff use for system administration.
