It's worse because huge chunk of Active Directory is essentially building on what MIT Athena did, which was heavily used with Sun as well - and all packaged into something that can be brought up operationally by SMB team with no previous experience

Building an AD-compatible service is not that easy, and it was not easy circa 2006, because there was a lot to reverse engineer. Sure, Sun had access to its own directory service (Sun DS), MIT Kerberos, BIND, OpenLDAP, NSS, and Samba, so it had a lot of the pieces, but there was a lot of work to be done putting everything together.

For sure. But Sun had great engineers, and it was a feature that I'd argue was visibly existential at the time.

Yes, Kerberos is a direct import, although extended quite a bit. AD is a lot more than Hesiod, but AFS is a lot more than SMB. Zephyr didn't make it over.

There was an opportunity to build out graphical management tools, but NIS+ kinda got in the way, and the politics of commercial Unix in general didn't help.

The nice thing with kerberos is that it v5 has extensibility effectively built in :)

I'd say the switch to DAP/LDAP was obvious better choice than Hesiod, and GPO essentially standardizes a lot of tooling that SIPB et al built for Athena as well

[deleted]