Over 10 years ago I deloyed Zentyal, which is a Linux OS that works as a drop in replacement as a domain controller. Active Directory, Outlook mail server and file server out of the box. I can only imagine it got better.
Azure AD, the cloud version, still isn’t as feature-complete (or possibly feature-bloated) as the original on-prem AD, which is a big reason large organizations won’t switch away from it.
AD is a security nightmare. EntraID requires internet but at least allows zero trust with diverse configuration and importantly without storing or holding session tokens or passwords locally.
For my company, the only blocker is file share, which can be migrated. All our with integration use ldap and can be migrated to openid. Luckily we don’t have more AD integrated stuff.
True, but so are all of the cloud platforms, so that doesn’t really set it apart. Being legacy tech at this point without a lot of new code being added regularly, most of the weaknesses are pretty well understood.
EntraID requires internet but at least allows zero trust
Yeah I’m not convinced that Microsoft as an entity actually grasps the concept of zero trust. I think they likely have their own internal definition of it, just like they had their own definition of web standards back in the Internet Exploder days.
Look at what happened recently with Edge, where they claimed that storing user credentials in cleartext was “intended behavior”:
EntraID also seems corporate established. For a modern with system, with zero trust etc, you use EntraID instead of AD now.
Of course, legacy AD systems, if they exist, are also lock-in.
Over 10 years ago I deloyed Zentyal, which is a Linux OS that works as a drop in replacement as a domain controller. Active Directory, Outlook mail server and file server out of the box. I can only imagine it got better.
EntraID is just a rebranding of Azure AD
Azure AD, the cloud version, still isn’t as feature-complete (or possibly feature-bloated) as the original on-prem AD, which is a big reason large organizations won’t switch away from it.
AD is a security nightmare. EntraID requires internet but at least allows zero trust with diverse configuration and importantly without storing or holding session tokens or passwords locally.
For my company, the only blocker is file share, which can be migrated. All our with integration use ldap and can be migrated to openid. Luckily we don’t have more AD integrated stuff.
True, but so are all of the cloud platforms, so that doesn’t really set it apart. Being legacy tech at this point without a lot of new code being added regularly, most of the weaknesses are pretty well understood.
Yeah I’m not convinced that Microsoft as an entity actually grasps the concept of zero trust. I think they likely have their own internal definition of it, just like they had their own definition of web standards back in the Internet Exploder days.
Look at what happened recently with Edge, where they claimed that storing user credentials in cleartext was “intended behavior”:
https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup/