We currently use passive authentication for web filtering using FSSO
with a collector agent installed on a local domain controller. We are
finding more and more situations where local domain controllers are
being decomissioned in favour of Azure base...