But if these cities are smart, they would pool their resources together to fund common tools. All the bits and pieces are already here. What is needed is a solid package that can be deployed and maintained easily, with user friendly GUI.
But if these cities are smart, they would pool their resources together to fund common tools. All the bits and pieces are already here. What is needed is a solid package that can be deployed and maintained easily, with user friendly GUI.
Difficult question: how do you make people in power agree on a solution? Not even universities managed so far to standardize their IT infra.
Germany is a country where one city orders would new trains which would eventually crash into the next city's platform due to different platform dimensions [0]...
[0] https://rp-online.de/nrw/staedte/duesseldorf/duesseldorfer-r...
Most universities probably already standardized on Microsoft's ecosystem of product and solutions.
Question is: why change for something open source?
Answer: licenses for MS are costing a fortune and privacy considerations.
Also, AD is becoming less comprehensive on windows, later versions of many MS packages require powershell and textual config additionally or solely. Not to speak of third-party software where AD group policy support was always spotty at best.
Yes, easy clicky setup is possible with AD, but your software options are severely limited, not even exchange is point&click-only nowadays
That's true, but Puppet and Ansible aren't meant for end user device management. They're primarily for deploying/running services. AD is the opposite, it's strong in end user scenarios and weak for running services.
Give it a bit more adoption, though, with more examples, snippets and tools, and that specific solution could do wonders. This is often a problem in the Open-Source world: little manpower, so works progresses slowly.
I'm pretty sure there are more (or less) obscure solutions.
https://guix.gnu.org/manual/devel/en/html_node/Invoking-guix... https://guix.gnu.org/blog/2019/towards-guix-for-devops/
Plus, it doesn't seem well suited to changing configuration on already deployed machines. If corporate comes and tells you all users must have their machines configured to automatically lock the screen after 5 minutes idle and enable some password requirements this tool would struggle.
I'll grant you that it seems to require a wizard to operate, or at least write a tutorial and investigate that use-case, but so does most software: I would be clueless in a AD environment, and it would take me a few hours to catch up on some basic concepts.
Now, it hasn't been designed with your specific example in mind (it could have been), so some wizard would most likely need to expose these knobs (lockscreen timeout, password policy)as easily accessible config items.
Don't most modern companies have web services for their internal apps? I don't have AD - I have an SSO web login for a variety of web sites and SAS products.
Who uses a printer these days?
File shares? That's Dropbox or Google Drive now.
Email? In your browser.
> These things all seem less and less important, though? Don't most modern companies have web services for their internal apps?
Actually it's more important than ever. All these cloud services means when staff leave there's more risk of an account accidentally being left open. Federated access resolves this problem.
> I don't have AD - I have an SSO web login for a variety of web sites and SAS products.
That "SSO web login" might still be Active Directory (it might not, but in many organisations it is).
> File shares? That's Dropbox or Google Drive now.
Or Microsoft OneDrive -- which would be authenticated against AD.
> Email? In your browser.
I'm a big fan of local mail clients but Microsoft have supported web mail longer than most people might realise. Quite a few years long than Google Mail. Longer even than Yahoo! Mail. OWA (Outlook Web Access) was first shipped in Microsoft Exchange 5 released sometime in mid to late 90s on Windows NT4. Sure, OWA was pretty basic but did a good enough job.
Microsoft also bought Hotmail back in '97
These days Microsoft have a pretty extensive suite of web-based office applications from Word and Excel through to Outlook. You might have heard of Office 365? Well that can also authenticate against Active Directory.
What Microsoft Active Directory buys you is easy integration with other Microsoft products like Windows; which is also a de facto standard in most organisations. However go anywhere that is a UNIX, Linux or Apple shop and Active Directory quickly becomes the wrong tool.
If it's not managed through the AD, it's often not allowed to exist. It's also (legitimate or not) often the reason to go for a microsoft tool or (azure) service, because it 'integrates more easily' with the access management stuff that is in place.
When IT administer thousands of Windows PC on domain, thats the kind of stuff they appreciate as it make their lives easier.
1. Remote management of company IT assets including individual users' computers.
2. Single source of truth for single sign-on.
3. Access control and remote configuration for network servers/resources.
If you dig further, there's even more stuff that connects into AD. For example, you can use it to set up and deploy internal certificate authorities for intranet apps.
If you're using Azure AD, you can extend single sign-on into non-Microsoft web apps. It includes an implementation of zero-trust networking.
The fact that it comes out of the box and is widely used is crucial, it means that as an IT professional you have less hassle with purchasing/configuring/deploying management software, and when you move between companies you already know the tools.
I think it's a good thing that governments are considering switching to Linux, but AD/AAD is a legitimately sticky product for IT management.
There's issues with Windows Server, sure, but AD and its relatives aren't one of them.
AD is a misnomer. It's not simply a directory. It not only does what OpenLDAP does but also what Kerberos does.
Openldap is aweful to configure by the way. The documentation is terrible, sometimes lacking important piece of information. I remember TLS being a pain to setup. Actually I think everything having to do with authentication (PAM, OpenLDAP, Kerberos, nss) on Linux is a pain to setup.
By comparison, AD is fairly nice.