Hello.
I am currently in the process of building a domain controller (Active Directory) VM in Azure (IaaS). And next is to set up one AADC in Azure and sync the users to Azure AD. I understand it is unusual but that is the requirement.
We have a domain controller on-premise (which will replicate with the domain controller in Azure). Workstations are already joined to the domain. However, they are not licensed. Which means we have not bought the CALs. The goal is to decommission the domain controller on-premise and make the domain controller in Azure as the primary domain controller.
My question is, do we need to buy CALs? Or subscribe to Azure AD premium P1? Or no CALs needed at all (based on this statement, "No. Windows Server CALs are not required for accessing Windows Server running in the Azure environment because the access rights are included in the per-minute charge for the Virtual Machines." From here https://azure.microsoft.com/en-us/pricing/licensing-faq/ ) We have about 2000 users authenticating to the domain.