I see this as a strict improvement for adoption of Linux workstations in the corporate world
MSIs still dont work on Ubuntu. GPOs are still very limited-- mostly just HBAC type stuff.
The stuff that works is the important stuff, but if people want to roll out software to Linux they aren't doing it with AD. They're doing it with a CM tool like puppet or ansible.
Also, it's kind of buggy. I have some Ubuntu 20 machines set to do AD logins here and more often than not it just stalls until it times out on login with no useful diagnostic messages emitted. Very frustrating.
Some environments mandate this stuff, and there's frankly no excuse for NOT supporting Kerberos / LDAP / centralized auth. The choice wasnt whether to support "stuff like this", but whether the support would be first class or second rate.
Some way of signing into Ubuntu with a custom SAML provider would be very cool. Windows supports it via their "credential provider"[0] framework and Google uses that to provide sign-in for Windows with your GSuite credentials.
[0]: https://docs.microsoft.com/en-us/windows/win32/secauthn/cred...
A bit frustrating, as you can otherwise join a windows 10 desktop (or vm) to just azure ad for sso etc.
[1] https://docs.microsoft.com/en-us/azure/active-directory-doma...
well that depends, the higher subscriptions include it for free.
sadly not for desktops, btw. you can create your own pam provider (grant_type=password) and put it into sssd (for local cache), but that does not work with 2fa.