If you already have an MS domain you could set up SAML login with ADFS (tried this, works fairly well) or AWS SSO if you have a managed AD in AWS (may not be available in your region). Also works very well with AzureAD as the provider, if you use that synced to your on-prem AD.