• NaibofTabr@infosec.pub
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      18 hours ago

      Sure, but they’ll have to catch up on almost 30 years of feature development (and feature creep). Active Directory is entrenched, by virtue of being the only game in town for decades.

      Not that they’re necessarily irreplaceable, but… a half-competent Windows Server admin can go from cold iron to running HyperV with a local domain (AD forest) with a SAN supporting 200 endpoints (assuming the hardware is already in place) pre-configured with end-user applications and all relevant network & security settings (via group policy), with a print server supporting local network printers, and be ready to enroll new users, in less than a day.

      I’ve seen it done, I’ve helped get it done. And all of that can be done with point-and-click GUIs, and not a dozen different ones, just like 3 (one for server/HyperV deployment, one for HyperV config post-install, and then basically everything else can be done through Active Directory).

      When you’re a sysadmin for a large organization, that kind of operation at scale is non-negotiable. When I say that AD really has no competition, that’s what I mean. You could accomplish all of the same things on Linux, but it would take you a week of punching through terminal commands just to get the server and the domain up and running, and once you were done the user management still wouldn’t be as flexible or feature-complete as it is on AD (especially if you need things like auditing, or physical access token integration like badges for authentication, or remote desktop support, or video conferencing that is linked to corporate email accounts).


      All of that said, if you happen to know of a group that’s actually working on a competitor for on-prem AD (not Azure AD/EntraID, the cloud system is very different and not really comparable) I would be very interested. It’s a problem that’s been on my mind for awhile now, and I’d love to get paid to actually work on it.

      • rynn@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 hours ago

        Hey I didn’t say it would be easy, you’re right there’s a ton it’s doing.

        Rebuilding what it’s doing though wouldn’t take 30 years, they’ve figured out the requirements which means a startup can start fresh and build something even cleaner that works full on premise but seamlessly leverages cloud services if you want them for backup / recovery situations in the event that your on premise systems have a failure.

        I don’t know anyone working on this but the fact that it would be hard means it’s actually not easily replicable and would be a good business for a startup to capture. The value prop is high for companies, if they could save a huge amount of money on licensing and get improved operational cost without sacrificing what they get from on premise it would be worth it.

        It would definitely be hard to get companies to switch but the potential savings and country independence parts might be enough to make them interested in paying the switching costs.

      • brimlar@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        17 hours ago

        You should check out JumpCloud. It frankly feels a lot like you’re living in a cloud-first, Microsoft-free future. It’s a dream to use and scales, manages Windows, Mac and Linux as equal citizens. We don’t even maintain on-premises servers (including domain controllers) anymore, we just use IP addressing from the firewall and patch, control, manage all our computers from one pane of glass.

        • NaibofTabr@infosec.pub
          link
          fedilink
          English
          arrow-up
          5
          ·
          17 hours ago

          living in a cloud-first, Microsoft-free future

          Oh really, whose cloud? Oracle?

          We don’t even maintain on-premises servers

          Ah, you’re dependent on someone else’s computers, someone else’s network architecture.

          That sounds awful.

          Nope nope nope, need on-prem only data, on-prem user account control, on-prem domain, absolute positive control of all outbound network connections with as few of those as possible, and no dependence on someone else’s monthly compute fees.

          Local always, remote only when absolutely unavoidable, and then stripped to the bare minimum. I’ll run my own NTP server so that only it has to reach outside for time updates, and every other local device can get time from it.

          NO. CLOUD.

          • brimlar@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            17 hours ago

            It’s fine to have these feelings, it just depends on your comfort level. For my home / personal life, I agree very much. For business, not so much (but, depends on your business).

            • NaibofTabr@infosec.pub
              link
              fedilink
              English
              arrow-up
              4
              ·
              edit-2
              16 hours ago

              OK, maybe no cloud is a bit extreme, I’ll grant that. Maybe your business needs some clunky, minimum-effort, rent-seeking SaaS crapware like Salesforce… fine

              IaaS? No. Nope. Not for anything we actually need.

              No cloud for anything required to manage and maintain the local network or user accounts. If the external network goes down, we’re still operational internally, we have our own domain and authentication servers, everyone can still login and run any locally deployed applications (which we prefer, so most of our business needs are served that way). We’re not going to lose corporate data to the latest AWS leak, we’re not going to be dead in the water because AWS East went down again, we aren’t going to have to reasess our budget because AWS raised their monthly fee again.

              It’s not about “feelings”, it’s about proper risk assessment and mitigation.

              You can outsource labor, you can outsource storage, you can outsource compute, you can’t outsource risk.

            • Appoxo@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              2
              ·
              16 hours ago

              For business you should be able to fully control the VM, back it up and restore it somewhere else.

              If you can’t do that ypu are chained.