The $40k bounty for this type of vulnerability is the ultimate insult. Staying on Azure is on the border of being considered a firing offense...
If there was a competitor to AD that is. Right now developers and hn peeps have loads of options for their work, enterprises do not. I have Windows clients to authenticate, I need AD. I need forwards/ backwards compatibility on my clients, therefore I need Windows. I have applications that must run for several decades therefore I need Windows.
Or look at some alternatives like...
"Setting up Samba as an Active Directory Domain Controller" - https://wiki.samba.org/index.php/Setting_up_Samba_as_an_Acti...