• rynn@piefed.social
    link
    fedilink
    English
    arrow-up
    60
    arrow-down
    2
    ·
    1 day ago

    Windows is basically a zombie OS at this point, shambling along and eating brains.

    • NaibofTabr@infosec.pub
      link
      fedilink
      English
      arrow-up
      34
      ·
      1 day ago

      Windows as a home user desktop is definitely coasting on momentum, though it is also the OS deployed on most new PCs which keeps it going.

      I think the only thing really keeping Microsoft relevant is Active Directory (and Azure by extension) because a lot of organizations are dependent on AD internally, and there still aren’t really any good alternatives that check all the same boxes. You could probably cobble together a working solution for ~90% of it with open source software, but it would be clunky, fragmented and feature-poor compared to an on-prem AD system. It would require a lot more administrative overhead to configure and maintain it, and user management would be a mess.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        8
        ·
        1 day ago

        I’m starting to see non-AD companies cropping up. If you have to support Mac and Mac is absolute trash on AD, you need to run software to manage the macs which can already manage windows. With all the remote work, even RMM software is on the rise.

      • Kissaki@feddit.org
        link
        fedilink
        English
        arrow-up
        7
        ·
        1 day ago

        EntraID also seems corporate established. For a modern with system, with zero trust etc, you use EntraID instead of AD now.

        Of course, legacy AD systems, if they exist, are also lock-in.

        • InFerNo@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          14 hours ago

          Over 10 years ago I deloyed Zentyal, which is a Linux OS that works as a drop in replacement as a domain controller. Active Directory, Outlook mail server and file server out of the box. I can only imagine it got better.

          • Kissaki@feddit.org
            link
            fedilink
            English
            arrow-up
            1
            ·
            9 hours ago

            AD is a security nightmare. EntraID requires internet but at least allows zero trust with diverse configuration and importantly without storing or holding session tokens or passwords locally.

            For my company, the only blocker is file share, which can be migrated. All our with integration use ldap and can be migrated to openid. Luckily we don’t have more AD integrated stuff.

        • NaibofTabr@infosec.pub
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          19 hours ago

          Sure, but they’ll have to catch up on almost 30 years of feature development (and feature creep). Active Directory is entrenched, by virtue of being the only game in town for decades.

          Not that they’re necessarily irreplaceable, but… a half-competent Windows Server admin can go from cold iron to running HyperV with a local domain (AD forest) with a SAN supporting 200 endpoints (assuming the hardware is already in place) pre-configured with end-user applications and all relevant network & security settings (via group policy), with a print server supporting local network printers, and be ready to enroll new users, in less than a day.

          I’ve seen it done, I’ve helped get it done. And all of that can be done with point-and-click GUIs, and not a dozen different ones, just like 3 (one for server/HyperV deployment, one for HyperV config post-install, and then basically everything else can be done through Active Directory).

          When you’re a sysadmin for a large organization, that kind of operation at scale is non-negotiable. When I say that AD really has no competition, that’s what I mean. You could accomplish all of the same things on Linux, but it would take you a week of punching through terminal commands just to get the server and the domain up and running, and once you were done the user management still wouldn’t be as flexible or feature-complete as it is on AD (especially if you need things like auditing, or physical access token integration like badges for authentication, or remote desktop support, or video conferencing that is linked to corporate email accounts).


          All of that said, if you happen to know of a group that’s actually working on a competitor for on-prem AD (not Azure AD/EntraID, the cloud system is very different and not really comparable) I would be very interested. It’s a problem that’s been on my mind for awhile now, and I’d love to get paid to actually work on it.

          • rynn@piefed.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            11 hours ago

            Hey I didn’t say it would be easy, you’re right there’s a ton it’s doing.

            Rebuilding what it’s doing though wouldn’t take 30 years, they’ve figured out the requirements which means a startup can start fresh and build something even cleaner that works full on premise but seamlessly leverages cloud services if you want them for backup / recovery situations in the event that your on premise systems have a failure.

            I don’t know anyone working on this but the fact that it would be hard means it’s actually not easily replicable and would be a good business for a startup to capture. The value prop is high for companies, if they could save a huge amount of money on licensing and get improved operational cost without sacrificing what they get from on premise it would be worth it.

            It would definitely be hard to get companies to switch but the potential savings and country independence parts might be enough to make them interested in paying the switching costs.

          • brimlar@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            19 hours ago

            You should check out JumpCloud. It frankly feels a lot like you’re living in a cloud-first, Microsoft-free future. It’s a dream to use and scales, manages Windows, Mac and Linux as equal citizens. We don’t even maintain on-premises servers (including domain controllers) anymore, we just use IP addressing from the firewall and patch, control, manage all our computers from one pane of glass.

            • NaibofTabr@infosec.pub
              link
              fedilink
              English
              arrow-up
              5
              ·
              18 hours ago

              living in a cloud-first, Microsoft-free future

              Oh really, whose cloud? Oracle?

              We don’t even maintain on-premises servers

              Ah, you’re dependent on someone else’s computers, someone else’s network architecture.

              That sounds awful.

              Nope nope nope, need on-prem only data, on-prem user account control, on-prem domain, absolute positive control of all outbound network connections with as few of those as possible, and no dependence on someone else’s monthly compute fees.

              Local always, remote only when absolutely unavoidable, and then stripped to the bare minimum. I’ll run my own NTP server so that only it has to reach outside for time updates, and every other local device can get time from it.

              NO. CLOUD.

              • brimlar@lemmy.world
                link
                fedilink
                English
                arrow-up
                3
                ·
                18 hours ago

                It’s fine to have these feelings, it just depends on your comfort level. For my home / personal life, I agree very much. For business, not so much (but, depends on your business).

                • NaibofTabr@infosec.pub
                  link
                  fedilink
                  English
                  arrow-up
                  4
                  ·
                  edit-2
                  18 hours ago

                  OK, maybe no cloud is a bit extreme, I’ll grant that. Maybe your business needs some clunky, minimum-effort, rent-seeking SaaS crapware like Salesforce… fine

                  IaaS? No. Nope. Not for anything we actually need.

                  No cloud for anything required to manage and maintain the local network or user accounts. If the external network goes down, we’re still operational internally, we have our own domain and authentication servers, everyone can still login and run any locally deployed applications (which we prefer, so most of our business needs are served that way). We’re not going to lose corporate data to the latest AWS leak, we’re not going to be dead in the water because AWS East went down again, we aren’t going to have to reasess our budget because AWS raised their monthly fee again.

                  It’s not about “feelings”, it’s about proper risk assessment and mitigation.

                  You can outsource labor, you can outsource storage, you can outsource compute, you can’t outsource risk.

                • Appoxo@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  17 hours ago

                  For business you should be able to fully control the VM, back it up and restore it somewhere else.

                  If you can’t do that ypu are chained.