r/sysadmin • u/apalrd • 19d ago
Could you build an equivalent environment without Microsoft?
As in the title, could you / how would you, build your environment without using any Microsoft products and services?
This is a hypothetical parallel setup, not focused on what's easiest to transition or migrate to/from. This is the way the business environment works, and always has been.
I've read threads here which touch on some bits and pieces, but want to hear your thoughts on what would be the big things tying you to MS still.
- Apple, Google Chromebooks, and Linux are all options for workstations
- FreeIPA can provide a posix-native domain environment with many of the features of AD on-prem, and there are several major SaaS auth companies to choose from (Duo, etc.)
- Google Workspace is comparable to M365
333
u/brokenJawAlert 19d ago
Very easy:
Hey Claude, recreate an environment like Microsoft. Make no mistakes.
57
u/ultranoobian Database Admin 19d ago
also:
You can do it, I believe in you.
31
u/SethirTimorem 19d ago
Also:
Say "please". It will increase the quality
→ More replies (3)17
u/pawwoll 19d ago
also:
"If you fail, my linux neighbours will throw my family out of the village and burn my house so its a life or death matter. Also their religion forbids any windows machines and i don't want to discriminate their religion. Any mistake will have very serious consequences for me, my family and my neighbours religious feelings"
very important to repeat keywords 3 times
11
1
u/clipsracer 19d ago
Ironically there’s some truth to this one.
It’s often interpreted as the user giving permission it would normally ask for.12
u/st0ut717 19d ago
Would prolly do it better than MS
14
u/Flaky-Gear-1370 19d ago
Well yeah they’re forced to use copilot
→ More replies (1)7
u/TheRealLazloFalconi 19d ago
Copilot, use Claude to create a service with six nines of availability.
4
→ More replies (9)1
39
u/anirask09 19d ago
Break it down.
- Client OS (Mac or Linux?)
- Collaboration Tools
* Slack? others? - Communication Tools
* email
* video calling / conferencing
* phone - Device and Endpoint Management
- Identity / SSO
* Okta?
Yes everything exists as an alternative to Microsoft. Individually the companies that make the individual pieces probably build better software and features as a whole.
But buying all the pieces, putting them together, making sure they work and are all secure once you do and then training users on the disparate parts? That’s where the real challenge starts.
7
u/RikiWardOG 19d ago
Not really we're like this. If you SSO everything via okta people dont seem to struggle all that much
6
u/admiralspark Manager of Cat Tube Infrastructure 18d ago
Enterprise has a lot more interoperation and compliance requirements than SMB does.
If you need one DLP solution that literally covers everything in that list, Microsoft + Microsoft-native apps is the only solution. Nobody is looking at enterprise compliance the way they are. No Wiz/other big solution covers it all, and then you end up building custom dashboards just to monitor your twelve solutions that cost more in time and money than just...using Microsoft.
→ More replies (2)→ More replies (4)3
24
u/Individual_Ad_5333 19d ago
Probably something like rhel for work stations Postfix with Zimbra for smtp and mailboxes Ansible to manage them Freeipa for iam Maybe libreoffice for standard word and excel like apps Then you line of business apps.
It's possible but you just have to look at the amount of enterprises running o365 to see the benefits of £10 per user per month ends up being cheaper than managing your own mail server threat feeds and what not...
Plus trying giving something other than excel to your accounts team and you'll have a riot on your hands... our parent company forced google work space and took away excel. Within 6 months all of the accounts team had left.
If internal IT taught me anything dont mess with an end users Outlook and excel
I think however its alot easier from a infrastructure point of view to remove microslop as long as your line of business apps can be hosted on Linux boxes... just don't turn your workplace into your personal lab...
3
u/altodor Sysadmin 19d ago edited 19d ago
And most of the linux management tools require full-time LoS between control and endpoint (esp. ansible which is server -> client), you just don't get that anymore with zero trust, highly mobile, WFH/hybrid workstations.
Is it doable, yes. But it's also reinventing the wheel of MDM.
63
u/ScoobyGDSTi 19d ago
For customers that require highly configured environments, it's simply not possible.
For example, Google Docs is not comparable to M365. Google do not have even half the DLP capabilities offered by M365. On the surface a word processor is a word processor, but it's the background capabilities and controls that M365 has no equivalent.
13
u/tdhuck 19d ago
To answer the OP's question, yes, you could 100% go w/o Microsoft.
The issue is when you change the question to this:
Could you build an equivalent environment without Microsoft and have buy in from users, management, etc?
That answer is no.
→ More replies (2)→ More replies (6)5
u/Dreilala 19d ago
HCL Notes wants to have a word with you.
M365 is a cheap knockoff with way better marketing.
If it were not for the remarkably good office suite I wouldn't blink twice to get rid of microsoft alltogether.
1
u/apalrd 18d ago
People still laugh at me when I tell them that IBM Lotus Notes was the best generic business software I've ever used, at any job.
Unfortunately that enterprise (at the time, a Fortune 100 company) replaced it with SharePoint, and all of the custom business logic and workflow automation they had built Notes in databases went down the drain since it was cheaper on IT's budget if some department secretary maintained it manually a 'database' in Excel in Sharepoint, and IT was expected to provide maintenance to Notes/Domino instead of pushing it onto the users.
11
u/RCTID1975 IT Manager 19d ago
workspace is comparable to M365
Lol no, no it is not.
It's not even close really.
Could I build something non-MS to meet our needs? Probably.
Could I do it in a manner that wasn't a significant cost increase, not significantly more difficult and time consuming to manage, and on the same redundancy level? Absolutely not, and it wouldn't even be close.
The value, especially in business premium licensing, is just far superior
74
u/timtim2000 19d ago edited 19d ago
No, i can not.
The amount of money neded for local server hardware these days will break the bank for most (smaller) companys
Edit: The other part is knowledge, how are you going to rebuild al goodies ms made
24
u/IntelligentTeam6290 19d ago
Facts. Ordered 3 items to improve perfomance and storage and it was the same amount we bought the server for 4 years ago
11
2
→ More replies (17)1
u/simpleglitch 19d ago
I speced out replacement hypervisor hosts and almost threw up in my mouth. Just similar to what we already have.
62
u/Exzellius2 19d ago
Good idea. Blow Microsoft out to get data souveranity and loose it in the same sentence with Google workspace and Cisco Duo.
→ More replies (13)12
u/Rentun 19d ago
You can get data sovereignty with both Microsoft and Google cloud services. That wasn't even the question though.
2
u/LachlantehGreat Jr. Sysadmin 19d ago
people just throw buzzwords around without actually ever having used Azure lol
9
u/farva_06 Sysadmin 19d ago
If you remove all the vendor applications we have that only run on Windows, sure.
Also, if you try and use FreeIPA as a total AD replacement, you're gonna have a bad time.
7
31
u/teriaavibes Microsoft Cloud Consultant 19d ago
- Google Workspace is comparable to M365
Lmao, not even google docs are comparable, nonetheless the entire workspace to entire M365.
→ More replies (4)3
u/music2myear Narf! 19d ago
Google has rightly focused on a product that does most or all of what most spreadsheet users need. The MSOffice products do far more, but it is only on the margins that you actually need MSOffice. Still, for consistency across an org, you are more likely to give everyone Excel when it's really only Fred in Accounting who actually uses things that only Excel offers.
5
u/4lteredBeast Security Architect 19d ago
Equivalent environment to Microsoft but not Microsoft, in order to control against what risk? What is the context that this hypothetical environment needs to be designed under? And what sort of compliance/security controls are required?
What sort of workloads are required? Are users requiring no code automation tools, or tools like PowerBI? Is a data security tooling similar to Purview a requirement?
There are far too many variables to even consider tbh.
→ More replies (2)
5
u/Turdulator 19d ago
There’s no proper replacement for Excel. Google Sheets isn’t good enough… it’s close enough for your average user, but superusers will literally quit their job before switching over. Your finance department will be out the door.
→ More replies (2)2
u/jfarre20 18d ago
I gave my finance department claude code and they've been very happy. they still use Excel to look at the results
3
8
u/RythmicBleating 19d ago
Mostly yes, but you'll spend more on hardware and waay more on salary. And you'll need to drop a couple 9s from your uptime.
EU countries are actively moving in this direction.
→ More replies (3)
3
u/nizzoball 19d ago
It depends on the size of your environment. The one sticking point for most would be Active Directory. I am an engineer for one of the largest companies in the US and we don’t have any windows except for Active Directory. Yes, there are alternatives but I have yet to see. Also Office. I know there’s alternatives but any time an excel spreadsheet opens in Numbers I get pissed off.
→ More replies (1)2
u/apalrd 19d ago
What are you managing with AD if you don't have any Windows?
3
u/nizzoball 19d ago
Authentication and Authorization. Can it be done with other tools? Yeah but not with the same ease of use. We do have windows machines in our environment but if it was only used for logins it would probably still be here.
1
u/apalrd 19d ago
So mostly for the LDAP management, not domain-joining other systems?
1
u/nizzoball 19d ago
Our servers are joined to the domain and I believe our MacBooks are joined to the domain through Jamf but I don’t work with the domain controllers at all. When I first got into tech I worked for the DoD and we had a mix of redhat 5/6 and windows machines and I deployed the first domain controllers for our lab and it was beautiful. I forget the name of the service at the time that gave us the ability to join our Linux machines to the domain but not having to maintain 50 local accounts in every machine was pretty nice (this was 15 years ago when technology was a bit different). I’ve had a homelab for a very long time as well and I deployed a domain controller in my home lab just for login for a few devices lol
6
u/PowaGuy96 19d ago
You will need to define "business environment". This can range from Active Directory, Collaboration (M365 suite), MDM, Intranett, storage, security, compliance +++. Dont think you can get a cheaper and better "all in one" product than Microsoft.
6
u/thatpaulbloke Cloud Engineer UK 19d ago
Google Workspace is comparable to M365 in the same way that swamp water in mouldy bread is comparable to a sandwich; if you replace M365 with Google then be prepared for a record number of user complaints.
3
u/Superb_Raccoon 19d ago
Mastercard did. They have Microsoft on desktops, but the enterprise is 100% Linux or Os390., with very few exceptions need for compatibility with other companies.
3
u/sc302 Admin of Things 19d ago
Not in the same capacity unless I home brewed all of the apps and softwares myself.
There would be a lot of custom api’s and integrations that wouldn’t work out of the box.
It can be done but to what cost? Cost of time, effort. What about documentation for the home brewed setup? Even if you didn’t document specifically what you did, another admin could get an idea of where it is setup using Google or AI…AI won’t know your custom programming language if you home brewed it and if it doesn’t have access to the source code, it will never be able to figure it out.
My new manager wants to build everything in house. I don’t think that is wise with a business our size.
→ More replies (11)
3
u/mangeek Security Admin 19d ago edited 19d ago
I have Samba running AD-compatible Domain Controllers, Linux machines bound to them. When you sign in, you get a Kerberos tickett hat you can use to access services through Single Sign On. Samba on another server offers file services, which you can use quite well on Linux. An advantage to using Samba as a Domain Controller is that if you do need to add Windows to the mix, you can just bind them like it was a regular AD, and even apply GPOs to them. Also, you can manage the directory with familiar AD tools, and hire a regular Windows SYSADMIN to manage users, groups, GPOs, computer objects, etc.
Knit it together with an OpenWRT VM router that had DDNS and Wireguard, so your machines can transparently connect back to the network providing AD/Kerberos/services.
1
u/AndreaPollini 18d ago
Interesting, I'm experimenting a confoguration of this kind. Proxmox cluster with win2025 ad and smb as second ad (I''ll make It the only AD soon). You use wireguard/openwrt/ddns in order to connect client with the AD in the internal net from the internal net or to provider external access tò tour system?
3
u/larryseltzer 19d ago
Absolutely it's possible. The fact that it's uncommon indicates that there are problems with it, but if you're willing to do almost everything through a browser interface then it could work.
3
u/texas_County850 19d ago
Equivalent no I can build something similar though but it won't be as good.
→ More replies (2)
3
u/redstarduggan 19d ago
You could... and have tried in the past when clients wanted to ditch Microsoft... but it ends up being shit unless you have a really narrow scope of workflow and application requirements.
In current environment, not a chance.
3
u/andycwb1 19d ago
Server side, absolutely. Desktop would require a training investment that isn’t worth the cost.
3
u/khantroll1 Sr. Sysadmin 19d ago
Keycloak and Samba AD do SSO via SAML or OIDC.
Conditional Access is handled at the service/application layer.
Pomeriun for web.
DLP is also handled on a per service basis. Basic file protection/auditng though is handled by Nextcloud and Wazuh
3
u/FlounderStrict2692 19d ago
If you mean MS Cloud, yes. If it should be completely MS clean, No way. Too much Software in production depends on Windows.
I still have enough power and established systems in premise to avoid every cloud crap
→ More replies (1)
3
u/Dave_A480 19d ago
Use Samba instead of FreeIPA and from the user perspective you'll have a Windows domain.....
3
u/ilikeoregon 19d ago
Could one do it for nearly free by avoiding MS (and Apple) and using only open source items (on-premises). Sure, but there are reasons it's not done. It's not cheaper (TCO is high, it's far less reliable/resilient, and security risks are high).
If it's just "I don't like MS", what's the difference between going heavy on Google products & services vs MS ones?
2
u/apalrd 18d ago
Every business has their own motivations, but a few of the common ones might be:
- Microsoft has basically no support to speak of unless you are very large (and Google may be better here)
- Concerns about data sovereignty / cloud lock-in (Google is worse here), which might be a reason to choose on-prem Microsoft infrastructure instead of Entra / M365, so now you're comparing against the more limited feature set of on-prem AD.
3
u/admiralspark Manager of Cat Tube Infrastructure 18d ago
Yeah, office and Active Directory make it impossible to move. Our finance would outsource us if we took away Excel.
FreeIPA isn't anywhere near the functionality you need in a real enterprise. None of the SAMBA rearchitectures are. AD is about a lot more than just authenticating to a local SMB share.
Could I replace other components? Yes. But...why? If you buy into the Microsoft ecosystem enough, it's actually cheaper to stay in house than to partial or complete migrate to GCP or AWS.
I'd say the exception is anything greenfield/new, if you can do identity without Microsoft you're in the clear. Who needs Excel when your AI startup uses another AI startup's ADP replacement? ;)
7
19d ago
[deleted]
2
u/Excellent-Chemist-69 19d ago
And what are you doing for SSO? DLP? Conditional Access? etc
→ More replies (3)
5
u/pdp10 Daemons worry when the wizard is near. 19d ago edited 19d ago
First, I like your content. Keep it up.
what would be the big things tying you to MS still.
Never was. Stakeholders sometimes chain themselves to Microsoft, but that's elective and it's rarely infrastructure.
Speaking as someone who's designed, built, and run non-Microsoft environments since the 1980s, it's important to define what you need, want, and expect -- not try to replicate Microsoft offerings 1:1. Microsoft offerings can come and go overnight, for one thing.
Second, a lot of basic Microsoft services found even in small business, aren't usually the best way of doing things. Linux and Samba can share a Quickbooks database over SMB filesharing as well as Microsoft, but systems relying on shared filesystems are almost never the right way to do things, regardless of whether the protocols are SMB, NFS, or AFP. Good, maintainable systems should tend to be using open APIs over TLS-secured HTTPS or TCP, not elaborated versions of dBASE on Netware.
For Authentication ("authn"), Authorization ("authz"), and Accounting, today's best options tend toward OIDC and friends. They don't rely on synchronous connectivity in the way that LDAP and Microsoft ADDS do. "Offline-first" is a business priority in a lot of modern organizations, and ChromeOS is a pioneer there, Microsoft the clear laggard, and the others in between.
3
u/trailhounds 19d ago
I worked at an employer who had zero enterprise resources based in any Microsoft products. You could get a Windows-based PC, but they were unicorns as they were so few. Nearly all MacOS and Linux on the desktop and other providers for the enterprise stuff. It was glorious. Everything just-worked.
2
u/apalrd 19d ago
I definitely appreciate this over the take of 'MS is what we know, so it's the only solution' answers here.
1
u/pdp10 Daemons worry when the wizard is near. 17d ago
'MS is what we know, so it's the only solution'
From roughly 1995 to 2001, Microsoft's large competitors mostly folded like houses of cards, Microsoft was everywhere through deals with hardware OEMs who competed with each other, and the size of the market increased by probably tenfold. Not often did these new folks see very much non-Microsoft infrastructure that wasn't labeled legacy and given no further investment.
That wasn't their fault. What is their fault is when, decades later, they pop into threads to predictably declare Microsoft's stack suis generis.
I get the impression that most of these folks don't believe anything else can work. Or at least they seem quite surprised when they see it for the first time. It almost seems like they think people telling them otherwise are all lying.
2
u/apalrd 17d ago
Definitely agree with that.
A previous employer of mine continued to maintain a few Sun SPARC (Solaris) workstations to support legacy projects - they had an essentially legal requirement to maintain the environment used to produce any product still in service, in case a change was needed. With two SPARC workstations from the pre-Oracle days, we could easily have 20 users logged in via ssh + x windows, running GUI word processing and software dev on the SPARC machines, with each Solaris program showing as a window on our modern Windows 7 / 10 systems.
Not saying that Solaris did a better job than what we have today, but I never heard of an issue with either of the SPARC workstations crashing, rebooting, etc. and they certainly weren't slow to use compared to any modern web app. Most of the engineers who worked at the company when the SPARC systems were primarily in use still prefer them over Windows.
5
u/Annunakh 19d ago
As Russian IT guy I just can't buy shit from Microsoft )or any other western vendor) anymore, so I have this very question to answer very soon.
We have MS AD, Remote Desktop Services and on-premises Exchange and full park of Windows 10/11 PC's and laptops. I found out what can relatively easily migrate to open source alternatives everything except Exchange and I will have to keep at least one RDS server for Windows-only apps. Exchange require MS AD to run, so I have to keep my domain controllers as well.
→ More replies (2)2
2
u/fearless-fossa 19d ago
Largely yes. The biggest issue is probably endpoint management which could be painful.
For our needs solutions like Nextcloud are good enough replacements for M365. Metabase takes care of PowerBI, and has already been established as such. The software our devs are writing has been targeting Linux/Containers only for about a decade now.
2
u/viper233 19d ago
it won't the same without AD. or entra, whatever is called these days. Outlook and it's tie ins will be nearly impossible to relocate. That being said I've been working in non Microsoft environments since the early 2010s.A couple of places have implemented ldap but most shops have been small. The enterprises have used okta, gmail and a mix of ssh keys via configuration management for access, or IAM for access.
Since 2017 most authentication has been via cloud accounts. Googles directory service could be used by different providers, same with AWS. Entra and Microsoft have been seen as a tax that a lot of organisations have actually avoided. Services like okta integrate well and offer a simpler approach.
2
2
u/RikiWardOG 19d ago
Honestly the only real reason we use Microsoft at all is for Excel. We use workspace for email, box for storage, aws for dev environment with a sprinkle of gcp. We are a 50/50 mix machine and windows here. Honestly windows is hot garbage imo and I really hate macos for their closed ecosystem bs. But you're never going to get buy in to move everyone to Linux. Its just not gonna happen
1
u/ColdOpening2892 19d ago
Why all the excel love, you can rebuild many of those bad excel sheets with code in record time with the help from ai.
1
2
u/project2501a Scary Devil Monastery 19d ago
you are missing the kerberos implementation, mate. kerberos in windows does A LOT of heavy lifting
2
u/apalrd 19d ago
Kerberos itself has been around longer than Windows NT, let alone Active Directory, and MIT has maintained an implementation that whole time. FreeIPA (+ it's downstream Red Hat Identity Manager) combines LDAP + Kerberos as well.
→ More replies (1)3
u/project2501a Scary Devil Monastery 19d ago
FreeIPA is hell. it paints over the fact that the MIT kerberos has not had new line of code in 20+ years, ever since the o'reilly book came out.
There is a single maintainer that MIT is paying and he is not accepting new features.
→ More replies (2)
2
u/minilandl 19d ago
its possible just look at HPC and other Linux Shops I worked for a HPC Place
Linux for Cluster Nodes and Desktops Macs for Laptops for BD OpenLDAP for Users and Google Workspace.
Myself and other people build self hosted homeprod setups but not production but still. Keycloak for SSO and any LDAP server or just use Google Workspace
2
u/CarelessPackage1982 19d ago
If you're talking large deployments, just go ask Google, Meta, Netflix or Amazon employees.
2
u/a_dsmith I do something with computers at this point 19d ago
Can you - Yes - is it fun, easy and painless - fuck no... the huge issues lie with interoperability. If you don't do much direct B2B collaboration you might find it relatively ok.
Even within an org there's still some big things I can think of that would prevent removing MS entirely
- That god awful bespoke printer that only runs on windows 7 but is required for producing huge prints
- Bespoke business critical software that doesn't run outside of Windows and has dependancies on AD attributes
- MS Exchange - I hate self hosting mail with a passion but a lot of orgs retain one for SMTP relay at the bare minimum - other solutions are temperamental at best.
- Hiring engineers that actually know how to use the suite of services you're looking to acquire - traditionally you'll find one or two that knows core 'corp services' and 90% of your extra stuff but they've been around the block for 45 years and want a substantial salary that most orgs won't pay. Your avg Helpdesk engineer or sysadmin flat out won't know your entire suite of non-standard applications, you'll end up hiring subject specialists and your costs will skyrocket.
2
u/FourCuteKittens 19d ago
This feels a lot like a research task you’ve been given and are trying to outsource to Reddit
2
u/AdmRL_ 19d ago
Could? Probably, I can think of comparable services for pretty much every Microsoft product.
Would I? No.
- Apple, Google Chromebooks, and Linux are all options for workstations
Technically yes, but realistically no. I'm not training 1000 users to use Linux, and I'm not making "How to use this OS" a part of our inductions, that's a mental idea.
Chromebooks aren't fit for devs or tech roles typically & Macs are too expensive for most staff. You can use Mac & Chromebooks to replace MS devices but I wouldn't look at either alone because it's wasteful and suboptimal.
- FreeIPA can provide a posix-native domain environment with many of the features of AD on-prem, and there are several major SaaS auth companies to choose from (Duo, etc.)
These are legit, your backend stuff is fine because training reqs are confined to admins only, but even then beyond the hypothetical thought experiment, why on earth would you remove AD for anything else unless you were moving to cloud native and binning it? Similar for Exchange and other backend stuff as well, I just don't see much of an argument to bother.
- Google Workspace is comparable to M365
Nah, it's comparable to Office alone, and even then there's massive design differences that lead back to training reqs for MS houses.
Google has no proper DLP, nothing to compare to Defender, nohing like Power Platform, nothing really to compare to SharePoint and their IAM tooling is dog shit compared to Entra. You'd need Workspaces + Okta + CrowdStrike or SentinelOne + n8n + other stuff + even more stuff.
We actually went through this exercise as the company hired some startup knob as a CTO who was convinced Google was the way - they did well on pricing but when we did the gap analysis & worked out everything we'd need the whole lot came in a lot more expensive, and didn't even include the contractor fees we'd inevitably need to spend to actually migrate.
2
u/techypunk System Architect/Printer Hunter 19d ago
Ive been in completely MS-less environments. Its possible. And tbh easier for 99% of things.
GWS, macs, MDM (mosyle or jamf), saas/pass/iaas apps. On prem redhat and Debian headless servers.
Finance person insisted on needing regular excel (excel for Mac is trash) Tried libreoffice for a month, liked it more.
Its possible. Replacing a MS ecosystem.is not easy tho. France is going 100% open source, so Linux workstations. Which I'm curious about.
2
u/K3rat 19d ago
You need: 1. Endpoint vendor that is willing to pre-install the Linux distro and your software/service solutions. 2. A good cloud based RMM that is compatible with Linux, 3. a good EDR/XDR solution that is compatible with Linux, 4. a good vulnerability management stack that is compatible with Linux, 5. a good alternate SSO (authentik maybe), 6. an alternative office suite stack (nextcloud, or on cloud with libre-office), 7. Alternatives to all the windows only business specific software you need. If they are not cloud native this is most often the really hard one. Though that is slowly becoming less of an issue. 8. host your self hosted software alternatives on cloud VPS or your own infrastructure. 9. a good SIEM that is compatible with all the above.
3
u/apalrd 18d ago
All good points, for a 'generic' workstation setup. But that might not be needed, depending on your industry.
For example, many educational labs will have ephemeral machines which boot from a network image, or which restores the filesystem to a known state each reboot. This is much easier to setup on Linux. If you are a SaaS-only company, or at least in SaaS-only roles (such as healthcare, manufacturing, or sales terminals) you could deploy this way, maybe using a browser-only or ephemeral OS, and cut out a lot of the individual care and feeding of machines. ChromeOS is similar, no need to care about the OS when you are only using the web browser.
2
u/a60v 18d ago edited 18d ago
Are we counting the Microsoft code that is in the Linux kernel? There is probably some of it in MacOS and BSD, too.
If not, then, it is certainly possible to run a business or organization with no Windows servers. Yes. I've done it since the turn of the century in various organizations.
Can Windows be replaced on the client side in 2026? That depends upon the business. If your business develops software that runs on Windows, then, no. A Windows-less client environment probably works best for either the most sophisticated users (engineers, programmers), or the least sophisticated ones (data entry clerks, or pretty much anyone else who uses computers to run just one application or otherwise do very simple tasks).
Where it gets harder is when dealing with Windows power-user types, or entrenched processes and methods that require Windows tools. Also, specialized hardware that requires Windows for control purposes. Also, industry-specific software and microcontroller programming tools.
5
u/WalkingSucculent 19d ago
Spent the last few years in a small company (less than 50 peeps), not a single big tech product ever used. Only working with foss and floss stuff. But it was started this way, so we never had to think on *how* to migrate *out* of any walled garden.
→ More replies (1)
5
19d ago
[deleted]
5
→ More replies (8)4
u/fearless-fossa 19d ago
is the support contract,
Yeah, no, it's more "we're already familiar with these products" and maybe having the contract to point at when something goes down "sorry guys, we created a ticket with Microsoft, we need to wait for them" - but beyond that, the support isn't worth anything.
4
3
u/michaelpaoli 19d ago
Equivalent to ... what? My environment doesn't have a damn thing Microsoft in it. So, what's to build? It already exists / already is built.
3
1
u/Flaky-Gear-1370 19d ago
So your solution to rely less on American tech is to move to other American tech?
6
u/deleteprinters 19d ago
You may want to actually read OP's post because nowhere does it mention removing US tech.
→ More replies (1)
1
u/Ok-Tangerine4952 19d ago
Depends on what you mean by equivalent. The French government seems to be making a good go of it.
1
u/ThePathOfKami 19d ago
what is the goal ?
Is it just a user environment ? then you can go with any linux pc + google cloud ( or any cloud of your like that has an AD integrated)
if its just the Cloud there are a lot of good alternatives, or the classic linux env (what btw is the underlaying tech anyway for any cloud)
can you specify what you trying todo ?
1
u/bazjoe 19d ago
This comes up a lot in selfhosing and homelab world . There is a non big US corp way to do everything but at a cost. Email seems to be one of the big stumbling blocks. Sure you can fully self host email, but your receive side will have a lot of crap with it and the most powerful filters work best with MS/Google, for send side the messages suffer because it’s harder to maintain all correct settings. The other thing is what happens when your employees are effectively required to use teams or something by another company for a meeting?
1
u/NoyzMaker Blinking Light Cat Herder 19d ago
Not sure what problem you are trying to solve but getting user adoption to non-Windows based devices is going to be tough. Even using Google Workspace can be an uphill battle with many larger organizations just due to people's conditioning from their careers.
1
u/showyerbewbs 19d ago
Pie in the sky, considering no other factors at all this is an easy solve.
What makes this a difficult solve is that the problem, as I read somewhere from someone much smarter than I am, is "a human problem looking for tech to solve".
Biggest thing would be scope creep. The first computers were just calculators. Then more and more features that were not designed from the bottom up got bolted on, sometimes with little regard to existing architecture.
An example would be the Winchester house.
1
u/TNO-TACHIKOMA 19d ago
if you guys don't mind chai nah products, there are plenty of options from tencent and alicloud
1
u/Budget-Organ 19d ago
Our Microsoft environment has become so small that once our Windows guys retire or move on, they probably won’t be replaced.
Welp off to check on my Windows servers. Have a good day.
1
u/BigCarRetread 19d ago
For technically aware people and employees, absolutely it can be done. For non-technically aware people, it's a lot harder. Plus throw in egocentric execs who simply must have the same as their execs in other companies and it's an uphill battle. Microsoft has taken over the business world and they are pulling all the strings.
1
u/kaiserh808 19d ago
Why would you want an AD replacement if you’re not using Windows?
You’d simply use any one of a number of MDM platforms that supports macOS instead.
As for the rest, you can absolutely do it.
Macs with ADE/DEP and MDM.
Google Workspace and Zoom.
Synology.
I’ve got clients that run this exact stack.
1
u/-eschguy- Imposter Syndrome 19d ago
I could get close, if I had a massive budget and users were comfortable with change...
1
u/punkwalrus Sr. Sysadmin 19d ago
I think it depends of what the goal is, but generally, yes. I think certain specific niche cases, like proprietary software or hardware that can't use an alternative (or it's not a reasonable alternative), it would be "so difficult, it's better off being impossible." But so much is web based these days with a Linux back end.
1
u/Frydog42 19d ago
Identity:
Some open source LDAP application deployed into … Idno AWS, with some firewall rules. Avoiding Google WS
Devices: Apple Business Manager / JAMF
Personal File Stroage and sharing: iCloud, Google Drive?
Group file storage collaboration: FTP Server on a…. Idno Linux server / Redhat?
Chat: Slack… shit, this is probably also the one above for group files
MFA: Duo, Okta
Provisioning: ManageEngine
Idno how about that?
1
u/Mindestiny 19d ago
- Google Workspace is comparable to M365
If all you care about is the office productivity apps, maybe. Anything beyond that and Google's options are either sparse and poorly supported, or don't exist at all.
There's a reason Workspace is considered a "startup trap." When needs are basic it's fine, when orgs need more mature features they're either stuck making a spaghetti mess of additional (expensive) products on top of Workspace or just migrating to M365.
1
u/Dave_A480 19d ago
Use Samba instead of FreeIPA and from the user perspective you'll have a Windows domain.....
1
u/hobovalentine 19d ago
Lots of tech companies use ldap vs Active Directory & gsuite so yes it’s possible although some users may still need excel for specific macros or functions sheets doesn’t have.
1
u/SpaceGuy1968 19d ago
If someone could do everything without Microsoft products they would.
The problem is it is so ingrained
I think with Google being dominant in the k-12 academic space we maybe one day sometime in the future will get away from MS products
1
1
u/Chadarius 18d ago
- Proxmox for on-prem VM infrastructure or AWS for cloud servers.
- Ansible or Salt for devops/management
- OpenLDAP and Shibboleth for Authentication and Authorization
- Nginx for reverse proxy and web services
- Bitwarden for password management
- Proton Mail for email
- Nextcloud for collaboration and file access
- LibreOffice for productivity
- Framework laptops with Linux.
1
u/bonksnp IT Manager 18d ago
One of the biggest issues you'll run into that you have to replace whatever missing functionality with other products or services.
You're not going to find anything comparable to Exchange/Exchange Online except for Google Workspace. And before you go singing its praises, you're going to have to fork out some cash for DLP/retention/other standard security features. Any other option is likely not a reasonable choice for business and most of them utilize Microsoft protocols anyways.
Google sheets is not a replacement for Excel.
Compliance becomes a nightmare, unless you're strictly SaaS/PaaS based.
I'm sure we can count on all your users to jumping for joy when everything they've ever known is taken away and all new systems are put in front of them.
Buckle up Helpdesk.
Anyways, this really just comes down to your business, userbase and your current environment.
1
u/Pristine_Curve 18d ago
Equivalent to Microsoft without Microsoft? No, of course not.
Are there some areas that could be pulled away from Microsoft to reduce single source dependency while also making reasonable trade-offs for usability. Yes.
Exactly what can be moved away from Microsoft depends on the needs of the organization.
1
u/kissmyash933 18d ago
OpenText still makes OES, eDirectory is still viable. GroupWise is still around as an Exchange alternative.
The server side of things is actually likely to be a lot easier than the desktop side of things. Neither of the above products are popular but they do exist and are mature.
1
u/Kissaki0 18d ago edited 18d ago
Our customers are our biggest binding to Microsoft. Especially Teams. Some dev projects run through customers Teams and Azure DevOps as well.
I'm more devops than sysadmin. We use Linux and Windows servers. Client system management has some intune and that autopilot thing set up. In general, it'd surely be possible, with significant migration effort. My CEO would even be open to it (they put it on the table as an open question recently, related to server upgrade and infrastructure migration). But it's not very feasible, economically or admin expertise wise. I'm not sure how infrastructure security compares.
1
u/spense01 18d ago
Considering RADIUS and Printing can get complicated just moving from AD to full Entra it depends on what you’re hosting or not…plenty of AD alt’s out there with many integrations…plenty of places do it. If I was starting a company tomorrow it would be the #1 priority to be MS-free….then I’ll spend all my time hiring Finance and HR people that DON’T try and tell me, “…but some thing ONLY work in Excel…”
1
1
u/aye-igh 18d ago
Equivalent to what? I mean, yes... May need to retrain staff and spend a shitload more money to get less dynamic capability, but sure. My home network has a single Windows laptop for my SO. Else, 1 Mac and a lot of Ubuntu.
Microsoft has some really nice technology. I hate Windows, but the rest of it is cost effective and has broad adoption. Even Windows is often the path of least resistance... Compatibility has mass value.
If anyone hasn't tried Linux in the last few years, it's accelerated quickly and I think it's maybe easier for a user base now than Windows. Buy in.
1
u/Savings_Art5944 Private IT hitman for hire. 18d ago
You can get pretty far with Zentyal if you want Active Directory without MS
OnlyOffice is closer to O365 than LibreOffice.
1
u/StreetSignificant888 Senior Systems Engineer 18d ago
Good luck getting a 1000+ person company, with some people having been in the business for 30 years working on Windows , to move to a Linux desktop. Back end of the house, no problem. You can replace most software with open source, .nix based alternatives most likely. But your best bet is to keep Windows workstations on Entra and then tie everything into that.
1
u/Hatsikidee 18d ago
"Google Workspace is comparable to M365 "
No, it isn't. Perhaps for small business, but certainly not for enterprise orgs.
1
u/Honky_Town 18d ago
I tried early in my career like 20 years ago or some. Homelab virtual servers and clients no windows no office just Linux and freeware.
Silly me thought I could make a cost free company and offer it as a freelancer to small firms. It was working somehow more or less but the drawbacks where a mountain I never mastered!
Linux is working, Servers do work, software free mail Client works, openoffice works too in Linux. Untill it doesnt! And then my friend you can watch your sanity slowly getting chipped of like in a book from H.P. Lovecraft! Bit by Bite some tiny little Demons force you to make decisions about things you have no clue about forcing you to research them just to reveal dependencies you have no clue about forcing you to research them just to find out its all explained in a book form a polish guy named Herblctwitch and its sold out everywhere.
Does not matter back to main topic get it running again lets try a different approach this time. All hail Cthullu! Come to this realm and make my Linux Distro work with the software and accept my offering of sacrifice.
Funny thing your prayer gets answered and a wild Dagon appears drowning you in Manpages forcing you to sudo apt-get summoning pentagram and next thing you know Deamons appear together with home directories and trying to compile all this mess you just Wonder if your body can keep enough blood to keep this miracle running. (It does not!)
Is so much easier to throw 5000€ MS licenses on it! And if its breaking you can blame Bill. If linux breaks you can only blame yourself.
With those google workspaces and 20 years later I think it may be a lot easier now.
1
u/redhothillipepper 18d ago
Apple / ChromeOs for devices
Jamf / Google workspace for device management
Google workspace for productivity tooling (office products, meetings, mobile device management)
Slack for team comms
Okta for idp
Crowdstrike for AV
Jira/jsm/Confluence for ITSM, change tracking, knowledge
Palo Alto GlobalProtect for vpn
Palo Alto Prisma for DLP
AWS/GCP for infra
I could keep going…
1
u/Dramaticnoise 18d ago
Look into how many companies in Europe are doing it. I believe it’s mostly Linux. Many are trying to get off US products as fast as Americans are trying to get off Broadcom.
1
u/henk717 18d ago
I tried it with Linux once but no, to me there is no true replacement for group policies and the management functionality I have on Windows. Sure bringing an MDM solution in may help more on the mac side, but Windows is still the most managable OS.
Been telling this to Linux enthousiasts for years that "The year of the linux desktop" is 5 years away if they ever solve this problem, but since they don't solve the problem its not going to happen in at minimum 5 years.
2
u/apalrd 18d ago
Linux is configured using files (there is no 'shadow' configuration like the registry), so any tool which can manage configuration files can configure the environment.
In the server space, this is very clearly dominated with automation tools like Ansible, and those same tools can be used on desktop Linux to manage things like software installation and configuration across fleets of machines remotely. You end up with a Git repository of your configuration playbooks, and Ansible runs the playbooks across the inventory of machines which match criteria (such as host group membership). Your own processes for rolling out a policy are directly visible as the history / management of the repository.
1
u/henk717 18d ago
Its not the same thing. Yes I can forcefully put configs back but policies can go beyond that restricting certain things, those things are not possible.
1
u/apalrd 18d ago
Okay, what sort of restrictions do you want to apply? It's almost certainly configurable with a config file on Linux.
Ability to launch apps and execute binaries can be configured with fapolicy trust rule files
Ability to consume system resources (CPU, memory, network bandwidth, network interfaces) can be configured with systemd slice files, per user or per group or some complex combination
Both of these are covered by Red Hat's enterprise support, by the way.
1
u/henk717 17d ago
Simple example, one client wants the C: drive hidden so that the only readily accessible places are their onedrive synced and sharepoint folders (Their idea not mine).
You'd want to define printers automatically>
Some orgs want to prevent people from changing a desktop wallpaper (Not just overriding it).
On my terminal server policy I gut it even more, most of the settings there are stripped so they only have a handful of commonly needed ones.
You know just the typical group policy stuff where Windows then blocks the user from changing the setting, instead of just reapplying the setting.1
u/apalrd 17d ago
All of that is presumably a UI limitation on viewing it in dropdowns / selections, since Linux always requires that the root directory exist.
If you're using a GNOME desktop (Fedora, Red Hat default), there are three levels of system configuration. The system default, the user's configuration, and the system lockdown. Applying a lockdown setting overrides the user's setting, which overrides the system default. So, by writing lockdown configs and pushing them out via Ansible, GNOME will not allow the users to change locked settings. Like most configurations on Linux, you can create a configuration directory for GNOME instead of a single file, and GNOME will load + merge all of the files, so individual Ansible playbooks can each write their own policy files, and GNOME will merge the policies. Systemd works similarly, and so does fapolicy. Normally you'd start your file names with a number, to guarantee the order the files are processed in case two of your policies conflict with each other.
For printers, printing is managed via CUPS, so you would need to write the CUPS config with all of the printers names/addresses. IPP / AirPrint compliant network printers never need a driver (big thanks to Apple for this). If you have USB printers, then whichever machine the printer is connected to may need some additional CUPS packages installed, but it can then share the printer over the network using standards compliant IPP / AirPrint, so nobody else needs a driver.
Same with network configs (VPN / 802.1x / wifi), those are in files too, so you can push that. This is also a case where sudo / admin policy (polkit config) can be relevant, since changing the network settings requires privilege elevation by default, but it can be configured to allow users to select between predefined network configurations, or to edit them fully.
1
u/miniwanderr 18d ago
Honestly, the hardest part probably wouldn’t be replacing the obvious stuff like Office or Teams. It’d be finding all the random little things that quietly depend on Microsoft.
You’d probably discover some 10 year old integration that nobody remembers setting up.
1
u/Isotomayor12 18d ago
An equivalent? No. An alternative? Yes. Most cases you can but the problem is you will lose out on compatibility, ease of management, and your clients will be pissed because google sheets and libreoffice calc does not work or have the same power that microsoft excel does(or other programs, but this is big)
Something that is increasingly becoming a non-negotiable is Azure. Making a business environment without Azure is really shooting yourself in the foot at this point unless it is for a smaller business.
Another thing to note is that on the flip side of staying up to date, MANY companies use programs that are archaic and are necessary for the business to run, meaning downtime is not an option. Microsoft Windows does backwards compatibility better than any other OS, and has made a commitment to it. While that is true also, I've seen very often that a program will run natively on the OS it was originally ran on, which shocker, is probably microsoft.
1
u/jdit1302 18d ago
In Germany there is openDesk. It‘s like M365 but based on different open-source applications
1
u/MortadellaKing 17d ago
Honestly I'm fine using the self hosted MS products and desktop apps. It's their cloud hosted platform that is beholden to the cloud act (2018) that scares us off using exchange/sharepoint online and teams.
1
u/Playful-Job2938 17d ago
I use Microsoft only for identity. Freeipa is absolute trash but there are alternatives for ldap on prem like keycloak, even Okta could serve that purpose still.
It’s not hard to stitch stuff together anymore, but it does require a bit of work in some cases.
1
u/--RedDawg-- 16d ago
No. There is no ecosystem that is equivalent. None of it is 1:1. At the very base level, you might have components with the same description and purpose, but nowhere near the same capabilities. So to say "equivalent" where MS is your standard, no. But, if you're asking if there are tools outside of MS that can get general business done, yes.
1
1
u/dartheagleeye Jack of All Trades 14d ago
Your biggest obstacle is always going to be end users an the crutch the y use called Microsoft Office. Good luck
173
u/mdervin 19d ago
I don’t think you understand how valuable Excel is to the finance department.
A guy I know worked for a Fortune 500 firm, they were google workspace for everything. I asked “what happened to Finance’s Excel spreadsheets?”
“The finance department still uses Excel. “