In Active Directory, Blog, Linux

Microsoft Active Directory® is the most common Windows-based user directory solution. AD leverages LDAP under the hood, but it largely uses Kerberos as the authentication protocol for Windows machines. Because of this, Linux and Mac devices struggle to integrate with Active Directory. AD is made up of three major components: authentication, authorization, and management. If a business uses 100% Windows devices, AD accomplishes all three tasks.

However, if a business uses any Linux or Mac devices, cloud infrastructure or applications, or non-Windows infrastructure, AD starts to fail.

If AD Fails, How are Businesses Managing Directories?

Active Directory Server failThere are several ways that organizations can connect their Linux devices to Active Directory. The easiest is by using LDAP via the PAM module.

Organizations can also use Kerberos under this model. However, instead of completely rectifying the issues where AD fails, each of these approaches creates extra work and could add security issues.

Another method is to leverage Samba and Winbind. This requires setting up Samba which is no easy feat.

The Better Approach to Making Active Directory Work with Linux Devices
Linux System Authentication

An alternative approach to connecting Linux or Mac devices to Active Directory is to leverage JumpCloud’s Directory-as-a-Service®, or DaaS. DaaS acts as an “extension” to AD, solidly fixing the areas where AD falls apart.

Directory-as-a-Service authenticates, authorizes, and manages all Windows, Mac, and Linux devices. Not just one of them – all of them.

Here’s how it’s done. Linux and Mac devices connect to JumpCloud’s cloud-based directory service via their native authentication mechanisms (and, through an agent). Users are added to JumpCloud’s virtual identity provider either via our Active Directory bridge, or they can be manually added. If Active Directory is connected through the JumpCloud AD bridge, then any updates in AD are automatically replicated to JumpCloud and, by consequence, to all Linux devices in the directory, too. For example, a new user can be added in AD and as a result given access to all of their Linux cloud servers hosted at AWS. The reverse is also true where a user terminated in AD is automatically deleted from the AWS servers. This is accomplished by an active synch process between AD and JumpCloud.

Through JumpCloud’s hosted directory service, Linux and Mac machines can be easily connected to Microsoft AD, eliminating headaches associated with manual management or work-around solutions with Chef or Puppet. Directory-as-a-Service is also a great directory choice for organizations that don’t use AD but would like to manage their Linux devices in a similar way.

Learn More About How to Make Active Directory Work With Linux

Feel free to give our AD to Linux/Mac connection a try with our cloud directory service. We offer a free account with 10 users free forever. If any questions come up or if you would like to learn more, drop us a note. We’d be happy to discuss whether DaaS is right for you.

Recent Posts