• NaibofTabr@infosec.pub
    link
    fedilink
    English
    arrow-up
    0
    ·
    19 hours ago

    Windows as a home user desktop is definitely coasting on momentum, though it is also the OS deployed on most new PCs which keeps it going.

    I think the only thing really keeping Microsoft relevant is Active Directory (and Azure by extension) because a lot of organizations are dependent on AD internally, and there still aren’t really any good alternatives that check all the same boxes. You could probably cobble together a working solution for ~90% of it with open source software, but it would be clunky, fragmented and feature-poor compared to an on-prem AD system. It would require a lot more administrative overhead to configure and maintain it, and user management would be a mess.

    • rumba@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      18 hours ago

      I’m starting to see non-AD companies cropping up. If you have to support Mac and Mac is absolute trash on AD, you need to run software to manage the macs which can already manage windows. With all the remote work, even RMM software is on the rise.

    • Kissaki@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      19 hours ago

      EntraID also seems corporate established. For a modern with system, with zero trust etc, you use EntraID instead of AD now.

      Of course, legacy AD systems, if they exist, are also lock-in.

      • InFerNo@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 hours ago

        Over 10 years ago I deloyed Zentyal, which is a Linux OS that works as a drop in replacement as a domain controller. Active Directory, Outlook mail server and file server out of the box. I can only imagine it got better.

      • NaibofTabr@infosec.pub
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        12 hours ago

        Sure, but they’ll have to catch up on almost 30 years of feature development (and feature creep). Active Directory is entrenched, by virtue of being the only game in town for decades.

        Not that they’re necessarily irreplaceable, but… a half-competent Windows Server admin can go from cold iron to running HyperV with a local domain (AD forest) with a SAN supporting 200 endpoints (assuming the hardware is already in place) pre-configured with end-user applications and all relevant network & security settings (via group policy), with a print server supporting local network printers, and be ready to enroll new users, in less than a day.

        I’ve seen it done, I’ve helped get it done. And all of that can be done with point-and-click GUIs, and not a dozen different ones, just like 3 (one for server/HyperV deployment, one for HyperV config post-install, and then basically everything else can be done through Active Directory).

        When you’re a sysadmin for a large organization, that kind of operation at scale is non-negotiable. When I say that AD really has no competition, that’s what I mean. You could accomplish all of the same things on Linux, but it would take you a week of punching through terminal commands just to get the server and the domain up and running, and once you were done the user management still wouldn’t be as flexible or feature-complete as it is on AD (especially if you need things like auditing, or physical access token integration like badges for authentication, or remote desktop support, or video conferencing that is linked to corporate email accounts).


        All of that said, if you happen to know of a group that’s actually working on a competitor for on-prem AD (not Azure AD/EntraID, the cloud system is very different and not really comparable) I would be very interested. It’s a problem that’s been on my mind for awhile now, and I’d love to get paid to actually work on it.

        • brimlar@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          11 hours ago

          You should check out JumpCloud. It frankly feels a lot like you’re living in a cloud-first, Microsoft-free future. It’s a dream to use and scales, manages Windows, Mac and Linux as equal citizens. We don’t even maintain on-premises servers (including domain controllers) anymore, we just use IP addressing from the firewall and patch, control, manage all our computers from one pane of glass.

          • NaibofTabr@infosec.pub
            link
            fedilink
            English
            arrow-up
            0
            ·
            11 hours ago

            living in a cloud-first, Microsoft-free future

            Oh really, whose cloud? Oracle?

            We don’t even maintain on-premises servers

            Ah, you’re dependent on someone else’s computers, someone else’s network architecture.

            That sounds awful.

            Nope nope nope, need on-prem only data, on-prem user account control, on-prem domain, absolute positive control of all outbound network connections with as few of those as possible, and no dependence on someone else’s monthly compute fees.

            Local always, remote only when absolutely unavoidable, and then stripped to the bare minimum. I’ll run my own NTP server so that only it has to reach outside for time updates, and every other local device can get time from it.

            NO. CLOUD.

            • brimlar@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              10 hours ago

              It’s fine to have these feelings, it just depends on your comfort level. For my home / personal life, I agree very much. For business, not so much (but, depends on your business).

              • Appoxo@lemmy.dbzer0.com
                link
                fedilink
                English
                arrow-up
                0
                ·
                10 hours ago

                For business you should be able to fully control the VM, back it up and restore it somewhere else.

                If you can’t do that ypu are chained.

              • NaibofTabr@infosec.pub
                link
                fedilink
                English
                arrow-up
                0
                ·
                edit-2
                10 hours ago

                OK, maybe no cloud is a bit extreme, I’ll grant that. Maybe your business needs some clunky, minimum-effort, rent-seeking SaaS crapware like Salesforce… fine

                IaaS? No. Nope. Not for anything we actually need.

                No cloud for anything required to manage and maintain the local network or user accounts. If the external network goes down, we’re still operational internally, we have our own domain and authentication servers, everyone can still login and run any locally deployed applications (which we prefer, so most of our business needs are served that way). We’re not going to lose corporate data to the latest AWS leak, we’re not going to be dead in the water because AWS East went down again, we aren’t going to have to reasess our budget because AWS raised their monthly fee again.

                It’s not about “feelings”, it’s about proper risk assessment and mitigation.

                You can outsource labor, you can outsource storage, you can outsource compute, you can’t outsource risk.