this post was submitted on 24 Nov 2025
233 points (98.7% liked)
Linux
10284 readers
630 users here now
A community for everything relating to the GNU/Linux operating system (except the memes!)
Also, check out:
Original icon base courtesy of lewing@isc.tamu.edu and The GIMP
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Endpoint (device) management is mostly a solved a problem, the challenge lies in integrated systems that allow secured, controlled, and constant access to data in a way that is manageable at scale by hundreds, thousands, or even hundreds of thousands of users.
That is where it gets wicked difficult and is what @Alaknar@sopuli.xyz is referencing. To my knowledge there is no real F/OSS equivalent to the tooling that MS Entra provides for IAM, DLP and MDM. You can maybe get close with a full deployment of NextCloud but that's really only replicating M365 functionality from 15 years ago.
Is it ultimately possible if you piece enough packages and systems together? Probably but it would be a massive plate of spaghetti that only a team of highly experienced *nix managers could hope to properly support.
You can definitely use a full F/OSS stack to replicate the functionality of a Windows Active Directory network but that's so last century. Today's organizations, no matter their type or size, demand more and they won't move to F/OSS unless they can get it.
I wouldn't call AD "last century." It is still deployed in many different places despite what Microsoft wants you to believe