this post was submitted on 18 Oct 2025
450 points (97.9% liked)
Linux
9963 readers
274 users here now
A community for everything relating to the GNU/Linux operating system (except the memes!)
Also, check out:
Original icon base courtesy of lewing@isc.tamu.edu and The GIMP
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
You just answered your own question; you can’t. Add in Group Policy Management and Active Directory and there is no windows replacement in any other OS.
Now mix in O365 and it just got more complicated.
If anyone knows of a 1:1 Linux equivalent for AD, GP, and DFS (both replication and namespace) I’d love to learn about it.
https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/7/html/windows_integration_guide/sssd-gpo
https://canonical.com/blog/new-active-directory-integration-features-in-ubuntu-22-04-part-3-privilege-management
https://dmulder.github.io/group-policy-book/intro.html
https://wiki.samba.org/index.php/Group_Policy
https://docs.delinea.com/online-help/server-suite/eval/nix-eval/configuring-the-basic-evaluation-environment/deploying-group-policies-to-unix-computers.htm
https://jumpcloud.com/platform/mdm
I've toyed with this in the past - is heavily lacks development. I personally would just use Ansible with SSSD configured to authenticate against active directory.
Only answering your last paragraph. You will not, ever, find a 1:1 equivalent for a few reasons, but mostly because:
Users can be centrally managed in a myriad of ways, but the most used software seems to be following the same X.500 standard - OpenLDAP, FreeIPA, etc.
Machines can be centrally managed via Puppet, Chef, etc.
Company software is managed by having your own repo.
SELinux can be used for incredibly granular access controls, but I can't see most companies actually needing that.
To sum it up - you'll always have trouble if you're solving a windows problem in linux and vice versa. Just for a moment, try imagining a situation where you want to switch a 100% linux company to windows.
Ok, so, no. There’s nothing that exists that’s a 1:1 for Active Directory and the services that come along with it.
This is why companies aren’t switching to Linux in mass.
OpenLDAP does.
There's not much to replace GPOs, but you can conditionally provision most settings on NixOS. Would be nice to build an MDM around Nix.
I can’t imagine that; not that it doesn’t exist but it’s rare.
I think you're missing the point of what I'm saying. Unfortunately, words are difficult enough to produce for me, I don't have a better way to express it.
That it doesn’t exist?
FreeIPA only really covers authentication and authorization. It also don't work well for remote devices such as someone's work device at home.
To properly manage a fleet of Linux devices you need some way of keeping all devices configured the same
Friends don't let friends use DFS
Seriously though it is prone to combustion
Distributed File System?
https://www.purestorage.com/knowledge/what-is-microsoft-dfs.html
That’s… that’s what I said.
When has DFS caught on fire?