Kerberos can’t survive in untrusted networks, and products like Azure AD and Okta are far more profitable, especially since the license that pays for AD (ie windows, even for Linux clients), is required anyway!
Kerberos can’t survive in untrusted networks, and products like Azure AD and Okta are far more profitable, especially since the license that pays for AD (ie windows, even for Linux clients), is required anyway!
Wasn't Kerberos designed to work in untrusted networks?
Azure AD DS (https://azure.microsoft.com/en-us/services/active-directory-...) is a specific offering from Azure which gives you a hosted AD instance, but otherwise AAD is completely different.
Additionally, with cloud email/office becoming the standard, there’s powerful levers to incentive cloud adoption and shifting of compliance standards.
I don't think this trend is as large as SV web devs think it is, nor do I think the trend will continue indefinitely in that direction. My current corporate masters hate the cloud because they want to be in control of their own data and services. They don't want to twiddle their thumbs when somethings wrong while waiting for BigCorp to get around to fixing it. They really, really don't like paying rent on business essential tooling.
And they've pretty much been proven right in all their concerns so far.
You typically need a more robust, web-compliant solution using e.g. tokens + MFA and web-compliant centralization of authority and certs on e.g. Consul or Red Hat Identity Management.
That being said, IMHO, it's a much saner and safer approach to bite that bullet and setup a rock-solid ID/Auth system on-prems (or at least vendor-agnostic and load-balanced over at least 2 major providers). It's really the kind of low-level infra that you can setup properly once and use for a decade, + cost of extra features you may want to add later.
Don't know what you're talking about, they work just fine. All of our branch offices and salesmen are remote workers.
Most places want to control capex and limit capacity wastage. Nobody wants to invest in datacenter facilities. Even the government, which has access to super cheap capital, is embracing cloud.
The shift is real. In my area, a major infrastructure OEM like HPE has like 2 CEs that cover the region. There was probably 14-16 20 years ago.
The answer is usually that legacy apps, SMB, Voip, and printing require trust derived from the network.