this post was submitted on 03 Feb 2026
567 points (94.2% liked)

Technology

80479 readers
3441 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] SuperUserDO@piefed.ca 6 points 1 day ago (1 children)

There is one last major bit once you have RMM and EDR in place - centralized identify. Until Okta, Ping, Azure, and Google all have a pam module that allows for remote identity management without depending on LDAP, enterprise endpoints are restricted to desktop/server machines (or orgs where you can get a waiver and only have local login).

[–] Buelldozer@lemmy.today 3 points 1 day ago* (last edited 1 day ago) (1 children)

Yep but...

Here's Microsoft - https://learn.microsoft.com/en-us/entra/identity/devices/sso-linux?tabs=debian-install%2Cdebian-update%2Cdebian-uninstall

Google has a variety of IDM methods including Ubuntu Authd and Secure Cloud LDAP. There's also 3rd party tools like JumpCloud, ScaleOrange, etc.

Okta appears to have ASA and OPA although I'm not familiar with either of them. Ping has PingID and Ping Federate, although again I haven't used either of them.

So depending on your cloud and needs the IdM / IAM is either available NOW or it will be very soon. 😀

[–] SuperUserDO@piefed.ca 2 points 1 day ago (1 children)

Ohh that's super exciting. I haven't realized Microsoft made one.

Okta's offering was garbage last I attempted to poke it. And 3rd party IAM tooling can be completely hit or miss (and let's not even start about LDAP over the web...)

[–] Buelldozer@lemmy.today 1 points 8 hours ago* (last edited 8 hours ago)

I dunno if it's exciting but I do have and use an Entra joined and InTune managed Linux Mint laptop with a full security stack loaded as described above. It works.