Business Central Insights
Most companies adopting Dynamics 365 Business Central should use the SaaS version. It's cheaper, Microsoft patches it, and there's no infrastructure to own. Some companies can't. If your data has to live in a subscription you control, if you're carrying a heavily customised NAV codebase, if you integrate with systems that will never touch the public internet, or if you're working toward CMMC or FedRAMP obligations — the on-premises edition of Business Central, on Azure infrastructure you own, is the answer. That's what we build. We just finished another one.
A defence contractor in Azure Government needed a working Business Central environment their team could evaluate before committing to a full implementation. We delivered:
Their users connected from their own laptops and worked through real transactions. Nothing about the system is reachable from the open internet.
Most guidance for putting Business Central on Azure ends the same way: public IP, DNS record, certificate, port 443 open to the world. It works, and it's more exposure than most finance systems warrant.
We build the other way by default. Users connect through a point-to-site VPN with per-user certificates — which means revoking one person's access is a single command that touches nobody else. Administrators connect through Azure Bastion, so there's no public RDP and no jump box to maintain. Network rules permit those two paths and nothing else; the database and application ports never leave the virtual network.
Where user counts make certificate distribution impractical, we front the web client with an Application Gateway and web application firewall instead. Either way, the principle holds: the server is not on the internet.
Not the installer. It's the connective tissue, and it's where internal teams and generalist IT partners lose weeks:
Certificates and authentication are coupled. Business Central's password authentication mode won't run unsecured, so choosing it commits you to certificate work on both the service tier and the web client — with the subject matching the exact hostname users type, the private key readable by the right service account, and a thumbprint recorded in configuration that must be updated at every renewal. Miss the last one and the system stops responding a year later for reasons nobody remembers.
Demo licence restrictions ambush project plans. The Cronus demo licence permits posting only within a narrow band of accounting periods, has no country-specific localisation, and isn't licensed for real data. We've seen testing weeks scheduled against a licence that made posting impossible for the entire month. Knowing this shapes the plan rather than derailing it.
Access to the subscription is assumed rather than confirmed. Tenant administration and subscription access are separate permission systems. "We have an Azure subscription" turns out to mean something different more often than you'd expect, and finding out on day one costs less than finding out on day ten.
Nothing is written down. A build that exists only in someone's head fails its first security review. We hand over a resource-by-resource reference document written for exactly that reader.
Business Central on Azure. Architecture, provisioning, installation, certificate and DNS setup, network hardening, secure remote access, user provisioning, backup, and handover documentation. Single-VM for evaluation environments; separated tiers, load balancing, and WAF for production. Built as code, so rebuilding is cheap and repeatable.
Business Central on Azure Government. We have delivered Business Central into Azure Government for a defence contractor — the deployment described above. Most Business Central partners have never worked in that cloud, and it is not simply the commercial build with a different portal address. Separate tenant and directory, separate subscription eligibility process, a different identity model, service availability that doesn't always match commercial, and isolation requirements that have to be designed in rather than bolted on afterwards. If you're under FedRAMP, CMMC, ITAR, or DoD impact level obligations, this is a conversation we're set up to have properly.
Migration from Dynamics NAV. If you're on an older NAV version with real customisation, we'll assess what carries forward and what needs rewriting before you commit to a path.
Evaluation environments. Sometimes you just need a working system with realistic data so your team can decide whether Business Central fits, before anyone signs anything. That's a small, contained engagement and it's often the right first step.
Infrastructure runs in your subscription, on your Azure agreement, at your rates. We don't resell compute or mark it up. An evaluation environment with auto-shutdown outside business hours costs very little; production sizing depends on users and transaction volume, and we model it with you before anything is provisioned.
Engagements are scoped and quoted before work starts. No open-ended hourly meters.
If you're weighing Business Central on-premises against SaaS, or you already know you need the on-prem edition and want it done properly the first time, book a call. It's free, it's a technical conversation rather than a sales pitch, and you'll leave knowing:
Book a scoping call and we'll go through your architecture, compliance posture, and timeline — no sales pitch, just a straight technical conversation. Or email us at [email protected] and describe what you're working with. Either way you'll talk to someone who has actually built these.
Book a Scoping Call →SureHoofERP deploys and supports Microsoft Dynamics 365 Business Central for companies that need control over their own infrastructure.