4 ms·
Windows, Office and Win Server (AD) make a combo that is quite difficult to replace. But if these cities are smart, they would pool their resources together to
by remir 6y ago
Windows, Office and Win Server (AD) make a combo that is quite difficult to replace.
But if these cities are smart, they would pool their resources together to fund common tools. All the bits and pieces are already here. What is needed is a solid package that can be deployed and maintained easily, with user friendly GUI.
- chrisseaton 6y agoWhat is the big deal about AD? A directory of your employees? What's so important about that? (I don't work in corporate IT I genuinely don't know.)
- jandrese 6y agoAD allows admins to apply policy (settings) to every machine in the organization at once. And to make sure the users don't change them. The policies cover pretty much everything, and can be applied as strictly or loosely as you want. There really isn't an equivalent for Linux. You can set up Linux equivalents for bits and pieces of it, but the all in one solution that you can just drop down on the network and hand over control to some 20 something fresh faced recruit straight out of college who has not been an admin is not there. This is a huge use case for AD.
- corty 6y agoAD for settings is a very poor replacement for what puppet or ansible enable on Unixoids. Also, AD is becoming less comprehensive on windows, later versions of many MS packages require powershell and textual config additionally or solely. Not to speak of third-party software where AD group policy support was always spotty at best. Yes, easy clicky setup is possible with AD, but your software options are severely limited, not even exchange is point&click-only nowadays
- munchbunny 6y agoAD for settings is a very poor replacement for what puppet or ansible enable on Unixoids. That's true, but Puppet and Ansible aren't meant for end user device management. They're primarily for deploying/running services. AD is the opposite, it's strong in end user scenarios and weak for running services.
- MayeulC 6y agoWell, I'm pretty sure there are some lesser known solutions out there. I've just learned about `guix deploy` for instance, which could make such a thing doable, and might be even easier to maintain in the long run. No pretty GUIs for now, though, and it configuring a setup seems to require at least a good understanding of guix/scheme. Give it a bit more adoption, though, with more examples, snippets and tools, and that specific solution could do wonders. This is often a problem in the Open-Source world: little manpower, so works progresses slowly. I'm pretty sure there are more (or less) obscure solutions. https://guix.gnu.org/manual/devel/en/html_node/Invoking-guix-deploy.html https://guix.gnu.org/manual/devel/en/html_node/Invoking-guix... https://guix.gnu.org/blog/2019/towards-guix-for-devops/ https://guix.gnu.org/blog/2019/towards-guix-for-devops/
- jandrese 6y agoThis is an example of a tool that solves only a slice of the problem and requires a wizard to operate it. Plus, it doesn't seem well suited to changing configuration on already deployed machines. If corporate comes and tells you all users must have their machines configured to automatically lock the screen after 5 minutes idle and enable some password requirements this tool would struggle.
- MayeulC 6y agoI'm not really sure why the tool would struggle, it seems like it was made for that use-case: running the command will ssh into each of the listed existing machines, perform some basic sanity checks, upload the new configuration (and packages in case of a system update), and finally atomically update the symlink, thus applying the new policy. I'll grant you that it seems to require a wizard to operate, or at least write a tutorial and investigate that use-case, but so does most software: I would be clueless in a AD environment, and it would take me a few hours to catch up on some basic concepts. Now, it hasn't been designed with your specific example in mind (it could have been), so some wizard would most likely need to expose these knobs (lockscreen timeout, password policy)as easily accessible config items.
- Spearchucker 6y agoAD is a directory of EVERYTHING. From users to groups, departments, divisions, printers, to remote access, device management, email, file shares... Many third party apps use it for either or both of authN and authR. You can use it to federate identities. It is vast in its scope and its reign is without equal.
- chrisseaton 6y agoThese things all seem less and less important, though? Don't most modern companies have web services for their internal apps? I don't have AD - I have an SSO web login for a variety of web sites and SAS products. Who uses a printer these days? File shares? That's Dropbox or Google Drive now. Email? In your browser.
- laumars 6y agoI don't like Microsoft much either and even I can still see your comments aren't fair > These things all seem less and less important, though? Don't most modern companies have web services for their internal apps? Actually it's more important than ever. All these cloud services means when staff leave there's more risk of an account accidentally being left open. Federated access resolves this problem. > I don't have AD - I have an SSO web login for a variety of web sites and SAS products. That "SSO web login" might still be Active Directory (it might not, but in many organisations it is). > File shares? That's Dropbox or Google Drive now. Or Microsoft OneDrive -- which would be authenticated against AD. > Email? In your browser. I'm a big fan of local mail clients but Microsoft have supported web mail longer than most people might realise. Quite a few years long than Google Mail. Longer even than Yahoo! Mail. OWA (Outlook Web Access) was first shipped in Microsoft Exchange 5 released sometime in mid to late 90s on Windows NT4. Sure, OWA was pretty basic but did a good enough job. Microsoft also bought Hotmail back in '97 These days Microsoft have a pretty extensive suite of web-based office applications from Word and Excel through to Outlook. You might have heard of Office 365? Well that can also authenticate against Active Directory.
- deleted 6y ago[deleted]
- Lutger 6y agoIt's the lifeblood of enterprise IT. The AD manages everything that is concerned with authentication and authorization, not only of actual employees but often also of service accounts (servers). If it's not managed through the AD, it's often not allowed to exist. It's also (legitimate or not) often the reason to go for a microsoft tool or (azure) service, because it 'integrates more easily' with the access management stuff that is in place.
- pletsch 6y agoDid a little bit of IT before dev, AD handles management of all the resources on the network. Authentication, backups, policies, Exchange for your email server is plugged into AD.
- remir 6y agoWith AD Domain services, you get a centralized resources administration, with stuff like group policies, easy way to share stuff like printers and files access. Single sign-on for all your users. When IT administer thousands of Windows PC on domain, thats the kind of stuff they appreciate as it make their lives easier.
- munchbunny 6y agoAD isn't just a directory. It's basically a central database that's connected to lots of useful corporate IT management tools that come out of the box with Windows: 1. Remote management of company IT assets including individual users' computers. 2. Single source of truth for single sign-on. 3. Access control and remote configuration for network servers/resources. If you dig further, there's even more stuff that connects into AD. For example, you can use it to set up and deploy internal certificate authorities for intranet apps. If you're using Azure AD, you can extend single sign-on into non-Microsoft web apps. It includes an implementation of zero-trust networking. The fact that it comes out of the box and is widely used is crucial, it means that as an IT professional you have less hassle with purchasing/configuring/deploying management software, and when you move between companies you already know the tools. I think it's a good thing that governments are considering switching to Linux, but AD/AAD is a legitimately sticky product for IT management.
- artonge 6y agoCan you explain the difference with openldap ? I have never used AD, and I am satisfied by openldap, I mean once I understood how to configure it...
- occamrazor 6y agoAD can be very roughly described as LDAP with a better interface, a consistent implementation and some proprietary extensions. You don’t need to fight with incompatible clients and have a decent UI. For the rest it is conceptually quite similar.
- corty 6y agoSchema versions in AD are problematic. Not every Windows Server version works with every Windows Client version. You always need to consult the support matrix, and for additional software like exchange that uses AD schema extensions, it gets even more complicated. So yes, if you are not strictly standardized to a single generation of Microsoft products, you do need to fight incompatible clients and servers
- jedieaston 6y agoYou can join any Windows 2k+ client to any version of Windows Server from 2000 onward, with the exception of Windows 10 to Windows 2000 Server, due to Win2k relying on SMBv1 for stuff. If you activate SMBv1 on Windows 10 it will join fine. Schema extensions are a different story, but I'm almost certain that nothing in that department has changed since Windows Server 2012. If you are doing a new Exchange install now and can't buy some upgrade licenses (or get an EA with Microsoft), you probably should be on Office 365 anyway. There's issues with Windows Server, sure, but AD and its relatives aren't one of them.
- brmgb 6y ago> I mean once I understood how to configure it... AD is a misnomer. It's not simply a directory. It not only does what OpenLDAP does but also what Kerberos does. Openldap is aweful to configure by the way. The documentation is terrible, sometimes lacking important piece of information. I remember TLS being a pain to setup. Actually I think everything having to do with authentication (PAM, OpenLDAP, Kerberos, nss) on Linux is a pain to setup. By comparison, AD is fairly nice.
- donjoe 6y ago... throw universities and schools into the pool also and you might finally get something which 'just works'. Difficult question: how do you make people in power agree on a solution? Not even universities managed so far to standardize their IT infra. Germany is a country where one city orders would new trains which would eventually crash into the next city's platform due to different platform dimensions [0]... [0] https://rp-online.de/nrw/staedte/duesseldorf/duesseldorfer-rheinbahn-ist-schuld-an-zu-breiten-zuegen_aid-33553137 https://rp-online.de/nrw/staedte/duesseldorf/duesseldorfer-r...
- remir 6y agoDifficult question: how do you make people in power agree on a solution? Not even universities managed so far to standardize their IT infra. Most universities probably already standardized on Microsoft's ecosystem of product and solutions. Question is: why change for something open source? Answer: licenses for MS are costing a fortune and privacy considerations.