I'm guessing you want to use the Azure AD Join as I know you use O365. 2016 is fine for this to use as single sign on. If you want to make use of the Privileged access management (PAM)in 2016 though you'd need your Active Directory forest functional level of Windows Server to be 2012 R2 or higher.
I can do this for you £550 + VAT per day.
I'll need a week to set it up and do some PEN testing.