Nowadays, you can comfortably live without local servers or even Active Directory.
On our MSP-side, our go-to stack nowadays is Microsoft 365 E3 + E5 Security (~$44/user/month). That gets you Email, SharePoint, Windows 10 Enterprise, full Office 365 and one-step-from-the-best security offerings. For your question, the important bits would be Intune, which you would use to set policies and install applications, Defenders for Endpoint/Identity, which you can think of as antimalware, and Azure AD for your identity and access management, which is your security, real-time threat management and multi-factor authentication. It's all cloud based which means you can manage it from anywhere, and the devices can connect in (and be properly secured and protected) from anywhere.
------------------------------
Steve Iwanowski, NextStep Technology Advisors, aka DSD Lancaster PA ¯\_(ツ)_/¯
------------------------------