Hi,
Yes that is the design or requirements for Azure AD DS you have to setup the Virtual Network and configure the VMs that are AD DS Joined to manage.
Check out the Azure AD Radius integration option - auth-radius
==
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.