Choosing the most cost-effective directory services solution means understanding your requirements. Modern directory solutions<\/a> will manage your digital estate across every device type<\/a> and resource, using stronger authentication methods than were previously available. Standalone Microsoft Active Directory (AD) is firmly baked into many organizations\u2019 IT infrastructures, but it doesn\u2019t accomplish those objectives. <\/p>\n\n\n\n
Microsoft\u2019s prescribed approach to AD modernization<\/a> entails combining AD with cloud services to manage a \u201chybrid of everything\u201d estate. Your infrastructure could span IoT, multi-cloud, on-premises, and operational technologies, and a directory provides access to everything<\/em>. Costs and complexity will vary depending upon requirements, licensing, and implementations.<\/p>\n\n\n\n
Check out the Ultimate Active Directory FAQ<\/a>.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Let\u2019s start with the essentials of operating server rooms. You must account for expensive hardware servers, which becomes costly if multiple servers are needed or if a company has multiple geographical locations that require their own fleet of servers. AD servers must be dedicated systems and meet very specific hardware requirements. This is a particular challenge for distributed environments which require multiple AD servers at each physical location.<\/p>\n\n\n\n
Cloud solutions either help reduce server room sprawl by providing services and scalability on demand, or can replace AD when the requirements are appropriate for a total migration.<\/p>\n\n\n\n
It\u2019s not uncommon for a server that meets your sizing and specification requirements<\/a> to cost five figures; although, it\u2019s not due to inflated hardware costs. It\u2019s because Microsoft has modified its licensing scheme to be based on a per core basis<\/a>. Client Access Licenses (CALs) are an additional fee. Here\u2019s what Windows Server licensing can cost for an 8-core server:<\/p>\n\n\n\n
Credit: <\/em>WintelGuy.com<\/em><\/a><\/p>\n\n\n\n
AD is focused exclusively on Windows devices, so a company needs add-on, third-party software to manage Mac and Linux devices. This is often licensed per device per user.<\/p>\n\n\n\n
<\/p><\/div>
JumpCloud is an open cloud directory that can reduce or eliminate these costs when it\u2019s used to modernize AD. Google recommends JumpCloud<\/a> for small and mid-sized enterprises to manage users and devices.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Hardening AD isn\u2019t a throwaway suggestion. Microsoft\u2019s literature and Microsoft Learn collateral urge customers to never sync on-premise admins to Entra, because AD can be compromised. A Microsoft shop should use Entra ID \u201conmicrosoft.com\u201d domain admins to \u201cbreak the glass.\u201d<\/p>\n\n\n\n
Microsoft\u2019s Cybersecurity Reference Architecture<\/a> (MCRA) prescribes cloud security solutions to protect AD against threats. That means subscribing to Entra ID Premium 2 (P2) for Identity Protection as well as licensing Defender for Identity. Defender for Identity can prevent lateral spread and privilege escalation. IT admins will first have to establish a hybrid configuration using Microsoft Azure AD Connect directory synchronization tool.<\/p>\n\n\n\n
Other suggested subscriptions and steps for hardening AD include:<\/p>\n\n\n\n
A percentage of a company\u2019s data center space needs to be allocated for networking equipment, as well as software that allows IT admins to manage and monitor the equipment.<\/p>\n\n\n\n
You should account for:<\/p>\n\n\n\n
An inert gas system requires sealing a room and having dedicated HVAC. Other solutions for special hazards, including in-rack fire suppression, are also costly. The following serves as an example:<\/p>\n\n\n\n
<\/p><\/div>
JumpCloud provides web SSO (OIDC, SAML), in addition to RESTful API-based provisioning, privileged identity management through conditional access, cloud LDAP<\/a> and RADIUS. It reduces your data center footprint by eliminating the need for the NPS server role and AD FS.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Installing, configuring, and maintaining an AD server, or servers, takes time and effort. A sizable portion of costs are put into resources, people trained and skilled to maintain the AD hardware and software, as well as the network equipment. When choosing a directory services solution, every organization should remember to factor in the cost for necessary patches and upgrades; otherwise, an entire business can abruptly halt if your system goes down.<\/p>\n\n\n\n
Windows Entra and Azure services require additional training and might necessitate new hires with salaries at market rates. Account for the training and certification costs of modernizing AD. Team members that use Entra AD have proficiency at the level of Microsoft\u2019s SC-100 and SC-300 certifications. Entra ID is an enterprise solution that has many interdependencies. Microsoft also recommends outsourcing automations and workflows to vendors.<\/p>\n\n\n\n
<\/p><\/div>
JumpCloud University<\/a> also provides training and certifications. However, it\u2019s possible for a small team to modernize AD without engaging with external resources. Cross-OS and browser patch management<\/a> for Macs<\/a>, Linux, and Windows is an optional add-on for JumpCloud.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Because AD does not have a central portal to handle password resets and other end-user problems, an organization needs to hire IT admins who can be on the frontline to assist employees with their devices and applications. Lifecycle management is a manual process without add-ons or automations, which provides low maturity entitlements management. Incidents such as the Colonial Pipeline hack<\/a> occurred due to stale account management.<\/p>\n\n\n\n
JumpCloud provides advanced lifecycle management by integrating with popular HR systems<\/a>. This helps to eliminate the barrier between HR and IT. Dynamic groups<\/a> automate user provisioning and memberships based upon attribute-drive rules. Google Workspace also utilizes attribute-based access control, and is complimentary.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Modernizing AD through Microsoft means remaining locked into its software monoculture through Entra ID, now, and for the foreseeable future. Security services, staff training, potential new hires, and external vendors to manage workflows raise costs. These costs are also locked in and go beyond the sticker prices of Microsoft 365 plans needed for Entra ID.<\/p>\n\n\n\n
Every organization should factor in what maintenance, add-on software, and IT staffing will cost if they continue to operate most services on premises. To help compare directory services solutions, we created a cost comparison calculator that you can use for a side-by-side comparison of Microsoft Active Directory with JumpCloud. Want a copy to simplify the process? Drop us a note.<\/a> We\u2019d be happy to send you our cost comparison calculator.<\/p>\n\n\n\n
JumpCloud provides a sensible and holistic approach to AD modernization; it also integrates with AD<\/a> and other identity providers (IdPs), such as Okta, through federation and directory synchronization. It\u2019s an even better solution when paired with Google Workspace for productivity and collaboration. IT professionals and MSPs can modernize or replace AD<\/a> with JumpCloud.<\/p>\n","protected":false},"excerpt":{"rendered":"