I've inherited a school which has gone server-less, just using 365 tools which seem to just about do the job, but I really feel we need some perimeter protection. Broadband company doesn't offer in-line filtering, and it seems like pieces of tin won't authenticate to Azure, though someone told me that Fortinet boxes do?
My options seem to be an agent-based solution (Lightspeed / Securly) which ignores the "network level guidance," or a DC in Azure (or on-prem) for authentication.
Oh, and we have satellite sites which complicates things even more, so I'm really interested in what people have to say.