Active Directory with Open Source, Part 2: Real Member Server ACLs, GPOs Without the Hype, and the Second DC

In Part 1, we set up our Domain Controller correctly: an operational realm that bypasses the .local trap, signed time protocols, and a robust versioned backup routine. However, we explicitly left three core promises for later because they represent the exact threshold where superficial tutorials abandon the reader: the file server operating completely decoupled from the DC, role-based folder privileges that actually work, and high availability via a secondary DC. Here, we deliver on those promises. And, keeping with our house style, we do it without the marketing fluff—every milestone comes with its honest infrastructure caveat. ...

18 de enero de 2026 · 10 min