The point isn't that but the fact that like a normal user, a normal business don't want to have to tinker with low level components to get the functionality they want. They desire to pay and get a working piece of infrastructure with low hassle (tho i get saying active directory being low hassle is weird).
I do not need to create it, it already exists. Yes, you can write your own pam module, but in general you do not need to.
> just use what Microsoft sells you.
Which means now your employees need to manually sync the MS and your internal databases. Depends on how much your employees time is worth for you. I mean a lot of companies do exactly that, but it is certainly not the cheaper option.
Also using what MS sells is also illegal. Not that anyone cares, as whole Europe ignores that, but when you meet a civil servant on the wrong foot, your company is toast.
I just looked up libpam-mysql and it is not no-code at all. And it looks like an unpaid community project which allows contributions from anywhere. That's not a true replacement.
So my configuration is this (I only redacted the company name, the remaining is copied verbatim):
users.host = /run/mysqld/mysqld.sock
users.database = Company
users.db_user = mail
users.db_passwd = $(secret-tool lookup user mail@mysql)
users.table = User
users.user_column = username
users.password_column = password
users.password_crypt = Y
> and it is not no-code at allThen tell me how I put your "no-code tool" into the VCS?
> no college degree required
Yeah, which nearly everyone has, but now you need to run through tons of certification programs instead. Which cost a lot of money, so you have the "Certified Rockstar Active Directory Consultant Adviser (TM)"
> it looks like an unpaid community project
> built by paid devs with a verifiable software supply chain.
Which is how most FOSS OS work, which have way more of a verifiable supply chain than your proprietary closed-source OS from Microsoft.
> it is not no-code at all. no college degree required.
Which totally matters, because you want random Joe who hasn't even finished college to be able to mess around with the company authentication setup.