Taking a spin off of this question: [Do I really need MS Active Directory?](https://serverfault.com/questions/13034/do-i-really-need-ms-active-directory) in a nouveau direction for 2014.
**Taking into account a basic Windows infrastructure:**
- domain controllers
- Exchange 2007/2010/2013
- Sharepoint
- SQL
- File Servers / Print Servers
- AD Integrated DNS
- AD authenticated 3rd party devices (let's say 802.1X for networking et maybe certains content-filtering, etc.)
- AD/LDAP authenticated "administrative" functions on IT apps/hardware/etc.
- perhaps certains KMS stuff
- throw in a CA si you'd like
- home grown apps
- 3rd party in-house apps
Now, let's rip it tous out et decide we are going to le cloud. We've contracted to move Exchange/Sharepoint/File Services to Office 365. SQL will now be hosted as well on something like Azure. We've gotten away depuis le need for AD-DNS et simply run everything via a simple Windows DNS server. We encore need 802.1X et would like SSO si possible to our various cloud apps. Home grown et 3rd party in-house apps would likely stay, mais have le ability to use internal user databases à la place of AD authentication
**The question is...do we really need Active Directory at all?**
Or more to le point, AD on-premise ou even hosted via Azure ou similaire (ADFS) ou running ADDS on a hosted VM through Azure ou similar. Could/Should we look to something else like a 3rd party SSO option such as [http://www.onelogin.com/partners/app-partners/office-365/](http://www.onelogin.com/partners/app-partners/office-365/) ou similaire that can provide SSO functionality even si it is as simple as LastPass ou similaire for chaque user?
**What kind of legitimate needs does AD fulfill si everything else in le cloud?**
**Could a MS-centric infrastructure get away avec pas having AD at tous si they move everything that previously relied on AD to SaaS offerings that didn't rely on AD authentication?**
Si une entreprise Windows migre « tout » vers le cloud, a-t-elle encore besoin d'Active Directory ?
Re: Si une entreprise Windows migre « tout » vers le cloud, a-t-elle encore besoin d'Active Directory ?
J'ai managed large numbers of workstations sans AD. I had power tools (Altiris Deployment Solution), mais it encore hurt in certain situations:
- Security auditor comes in et says that our par défaut workstation password policy n'est pas good enough. In order to change password complexity et expiration, etc., on 5,000 machines, we had to write a (nontrivial) script et schedule that to run on tous machines. (Good luck catching le laptops, by le way!)
- Mapping department printers. Sure, we could use le IP number. That means that si Department A et Department B get into a printer war, le remedy involves staking out le printer et alors suivant le offender back to leur workstation to supprimez le printer depuis leur workstation. (I suppose you could buy print management software instead.) Also, how did that printer end up on leur workstation in le premier place si they're pas supposed to use it, et how will you prevent it depuis ending up there again?
- Il y a registry keys for WSUS, so you *technically* ne need AD for patch management. Cependant, si you include those registry keys in le image, you need to make sure et delete a couple of keys (SusClientID et PingID) ou else they will *never* get updates ever. Or, to be more spécifique et accurate, seulement one of them will get updates.
- Software installs. Vous pouvez do these avec power tools (LANdesk, Altiris, etc.), mais c'est extra money.
- "Poison" printer drivers. J'ai seen a couple of these. The best remedy was a print queue avec an updated driver.
- Windows 7 printing would have epic tantrums sauf si we set allowed forest/allowed hosts in point et print restrictions. Perhaps this ne voudrait pas be a big deal si tous printers were ip-only, as long as User1 jamais wants to use User2's local printer. Without AD, our techs had to soit use gpedit on le workstation ou on le master image.
- You're assuming cloud Exchange, mais Je suis aussi going to add that email migrations et autre large infrastructural changes sans AD are painful on le client end. I scripted le "remove software depuis old failed migration/add workstation to AD/migrate user's profile depuis local to domain/demote user depuis admin to power user/make changes to firewall" jobs et ran them through Altiris. (The Microsoft consultants were suggesting we hire temps avec thumb drives jusqu'à I showed them mon kung-fu.)
Also, there are software vendors who look at you like you have three heads quand you tell them you have workgroups plutôt than domains. Altiris runs in workgroups, mais votre desktop techs are jamais allowed to changez leir passwords, par exemple. (Okay, okay. They can changez leir password. But they aussi have to swing by votre cube et type leur nouveau password into le server, ou *tell you* what leur nouveau password is.)
What Je suis getting at is: Vous pouvez manage lots of workstations sans AD, mais you may need to buy replacement software, et even avec nice software you'll run into painful things.
- Security auditor comes in et says that our par défaut workstation password policy n'est pas good enough. In order to change password complexity et expiration, etc., on 5,000 machines, we had to write a (nontrivial) script et schedule that to run on tous machines. (Good luck catching le laptops, by le way!)
- Mapping department printers. Sure, we could use le IP number. That means that si Department A et Department B get into a printer war, le remedy involves staking out le printer et alors suivant le offender back to leur workstation to supprimez le printer depuis leur workstation. (I suppose you could buy print management software instead.) Also, how did that printer end up on leur workstation in le premier place si they're pas supposed to use it, et how will you prevent it depuis ending up there again?
- Il y a registry keys for WSUS, so you *technically* ne need AD for patch management. Cependant, si you include those registry keys in le image, you need to make sure et delete a couple of keys (SusClientID et PingID) ou else they will *never* get updates ever. Or, to be more spécifique et accurate, seulement one of them will get updates.
- Software installs. Vous pouvez do these avec power tools (LANdesk, Altiris, etc.), mais c'est extra money.
- "Poison" printer drivers. J'ai seen a couple of these. The best remedy was a print queue avec an updated driver.
- Windows 7 printing would have epic tantrums sauf si we set allowed forest/allowed hosts in point et print restrictions. Perhaps this ne voudrait pas be a big deal si tous printers were ip-only, as long as User1 jamais wants to use User2's local printer. Without AD, our techs had to soit use gpedit on le workstation ou on le master image.
- You're assuming cloud Exchange, mais Je suis aussi going to add that email migrations et autre large infrastructural changes sans AD are painful on le client end. I scripted le "remove software depuis old failed migration/add workstation to AD/migrate user's profile depuis local to domain/demote user depuis admin to power user/make changes to firewall" jobs et ran them through Altiris. (The Microsoft consultants were suggesting we hire temps avec thumb drives jusqu'à I showed them mon kung-fu.)
Also, there are software vendors who look at you like you have three heads quand you tell them you have workgroups plutôt than domains. Altiris runs in workgroups, mais votre desktop techs are jamais allowed to changez leir passwords, par exemple. (Okay, okay. They can changez leir password. But they aussi have to swing by votre cube et type leur nouveau password into le server, ou *tell you* what leur nouveau password is.)
What Je suis getting at is: Vous pouvez manage lots of workstations sans AD, mais you may need to buy replacement software, et even avec nice software you'll run into painful things.