Because we are a MS/Office/Exchange/OneDrive/Azure based organisation (and network hardware is not always the same at partner sites), we have deprecated the use of all local servers and storage. Virtually all communication is "up-and-down", rather than laterally; this is remarkably liberating, and simplifies many previously involved use cases. I can strongly recommend it, at least on a trial basis.
One of the tools we are investigating is the YubiKey, which facilitates authentication, including 802.1X. I'd say it is worth a look, https://www.yubico.com/ , they are used by an interesting mixture of organisations including Microsoft, CERN, Google, UK Government, US State Government and Novartis, amongst others. 802.1X may require some stuffing around, depending upon how it is implemented.