.
How Samba Active Directory Reduces IT Department Costs
Published on 7/17/25, 12:08 p.m.
Why IT Departments care about Active Directory generally hasn't changed much since it first launched multiple decades ago. Users and Devices need to log in to IT Environments securely, reliably, and provide other useful related capabilities. IT Departments need to centrally manage these same Users and Devices logging in for many sensible reasons. But in all this time what IT Departments care about when it comes to Active Directory functionality and features has not changed much, and a lot of related IT Department costs have stayed the same or increased. While Windows Server is the most typical way to implement Active Directory, an alternative has been production ready since late 2012, that being Samba Active Directory. Samba Active Directory brings substantial cost savings to IT Departments in contrast to Windows Server Active Directory, but how are those costs realised?
When LANified! IT Services engage with clients regarding migrating from Windows Server Active Directory to Samba Active Directory we exhaustively evaluate the technical feasibility of this. Take note that there are reasons why migrating to Samba Active Directory does not make sense, but we will not go into that in this Article. So for the sake of explanation, we will presume that we are talking about circumstances where migrating to Samba Active Directory makes sense in all regards for any examples presented in this article. Also keep in mind Active Directory functionality (such as Grop Policy Objects) and management tooling (such as RSAT) is retained when migrating to Samba Active Directory, so we will also presume no important functionality is lost either.
Cost Savings Areas
These are the primary areas for cost savings with Samba Active Directory:
Licensing Costs
It is common knowledge that Microsoft products such as Windows Server has licensing costs, but where all those licensing costs actually exist and how they work is also commonly misunderstood, especially relating to Active Directory. At first glance it might appear that Windows Server licensing for Active Directory aspects is a rather affordable cost of doing business, not really warranting a migration to Samba Active Directory. However we at LANified! IT Services often find our clients surprised to learn what actual Microsoft license compliance costs compared to what they have been paying. Typically the real number is a lot higher than previously anticipated. These costs are also not one-time costs but over time are typically repeat costs, even when permanent licensing is purchased (as opposed to Volume Licensing or Software Assurance options from Microsoft, which also are substantial in their Total Cost Ownership).
The Microsoft licensing considerations for Windows Server Active Directory typically break down into these areas:
- Windows Server Operating System Licensing
- Active Directory Client Access Licenses
- Active Directory Device Access Licenses
- DHCP Server Licensing Obligations
- Note: The below details namely talk about permanent Microsoft licensing and do not talk about subscription based licensing cost details such as Volume Licensing, Software Assurance, or other similar non-permanent licensing methods. The subscription based licensing is mostly the same in scope, but has different costs and rights that we will not cover in this Article. Samba Active Directory can also provide substantial IT Department costs savings in subscription based licensing scenarios also.
Windows Server Operating System Licensing
At the bare minimum at least one Windows Server installation is required to run a singular Windows Active Directory Domain Controller. However it is industry best practice to have multiple Active Directory Domain Controllers for IT Departments, leading to multiple Windows Server installations for AD Domain Contollers. This is further expanded for IT Departments serving multiple physical sites (such as offices in other regions) which often involve Windows Server Read Only AD Domain Controllers, in addition to the primary Windows Server AD Domain Controllers. All of these require Windows Server Operating System Licensing.
In contrast, Samba Active Directory has zero default licensing costs for the underlying Operating System as it runs on Linux (such as Ubuntu), this is true at any scale.
Let's explore some cost savings numbers between the two.
- Example company has 3x Windows Server installations each running their own AD Domain Controller. They also have 5x remote office sites, each large enough to warrant an on-premise Read-Only AD Domain Controller. So that's 8x Windows Server installations, each requiring Microsoft licensing for compliant editions of Windows Server.
- Considering these Windows Server installations are probably running each in their own Virtual Machine that is expected to be able to Live Migrate between Virtualisation Hosts, then OEM licensing for Windows Server is not going to be compliant and cannot be considered reasonable for use.
- As of July 17 2025, Microsoft is the primary provider of licensing that can Live Migrate between Virtualisation Hosts while maintaining compliance. The cost for each "Windows Server 2022 Standard CAL 16 Core License Pack + 5 CALs" is $2,071 CAD as of this writing.
- In our example scenario just the Windows Server OS Licensing for 2022 edition would cost approximately $16,568 CAD before taxes or other considerations are added. This does not include other related licensing costs, which are outlined further in this article.
- These licenses are NOT transferrable when upgrading to Windows Server 2025 or later year editions and must be repurchased.
- These costs will double or more if one or more of your Virutalised Hosts have more than 16 physical CPU cores available for use by any Virtual Machine as Windows Server licensing is tied to physical CPU Core count availability, whether they run on those Virtualised Hosts or not.
Did you notice the part mentioning that these licenses are not transferrable to newer editions of Windows Server? When you purchase permanent Windows Server Operating System licensing, that licensing is for that specific year-edition of Windows Server. So if you are using permanent licensing of Windows Server 2022, that same licensing CANNOT be used for Windows Server 2025 or later year-editions. Microsoft defines End of Life dates for all editions of Windows, and those dates are tied to the relevant year-edition. Windows Server 2022 (for example) will stop receiving Mainstream Support (Security and Other Updates) from Microsoft on October 13 2026 (based on definition observed as of writing of this article), and earlier year-editions of Winodws Server have even earlier End of Life dates set. Typically IT Departments address this by buying Windows Server OS licensing yet agin for newer year-editions. So that $16,568 CAD example above is doubled or more when the relevant Windows Server year-editions are replaced with newer ones. And these costs can also change in nature if Microsoft adds new requirements and limitations (such as they have done in the past by adding CPU Core count and Virtualisation related pricing and limitations).
Samba Active Directory does not have these licensing costs whatsoever. If you have Samba Active Directory Domain Controllers on Ubuntu 22.04, and you want to upgrade them to Ubuntu 24.04, then it costs you $0 CAD in licensing (or whatever your currency is) as Ubuntu does not have default licensing costs, and neither does Samba Active Directory itself. Additionally Ubuntu and Samba Active Directory do not have CPU Core tied licensing costs at all, in contrast to Windows Server having such licensing costs.
Active Directory CALs
But wait, there's more! Windows Server OS Licensing doesn't cover the whole licensing obligation picture when it comes to Windows Server Active Directory. There are also CALs (Client Access Licenses), DALs (Device Access Licenses, outlined later), and DHCP Server Licensing obligations (outlined later). Let's take a look at what costs for IT Departments can look like for CALs.
In the example company scenario above, we identified there is a head office and 5x remote office sites, as well as 8x Windows Server OS installations running AD Domain Controllers. With a company that has this many office sites they could have a user count in the realm of 1,000 users that log into Active Directory as part of their duties so let's use that number. In order to be compliant with Microsoft licensing in this scenario, the example company must also have 1,000 CALs as a minimum. Chances are they probably want more as they are likely to hire more staff over time, but for the sake of simplicity we're going to use the static number of 1,000 CALs that need to be owned. We also have established that they are using Windows Server 2022 as their year-edition, so this means the company needs to own 1,000 Windows Server 2022 CALs, as CALs are only for a specific year-edition.
In contrast, Samba Active Directory does not require any CALs at all. Note: this is only when all AD Domain Controllers are Samba AD Domain Controllers. The licensing is a lot more complex when mixing Windows Server AD Domain Controllers and Samba AD Domain Controllers for the same AD Domains/Forests.
Let's explore some costs savings numbers between the two:
- An example cost of 1x CAL is from CDW who lists a single "Microsoft Windows Server 2022 - license - 1 user CAL" at $93.99 CAD (before taxes, etc). This is a typical cost and you will find similar pricing elsewhere. Also note this is a permanent license, not a subscription-based license.
- This translates the 1,000 CALs required for the example company into an IT Department cost of $93,990 CAD.
- These CALs are NOT transferrable when upgrading to Windows Server 2025 or later year editions and must be repurchased. Typically this doubles the CALs costs or more each time.
- As the example company grows, and more users need to log on, the company will need to purchase additional CALs to remain in license compliance.
In-contrast, Samba Active Directory (when there are no Windows Server AD Domain Controllers used) has no CALs whatsoever. There is no licensing limitation to how many users can use Samba Active Directory, so as the example company grows, if they were using Samba AD Domain Controlers solely, then they would not incur any additional costs related to Samba Active Directory. Additionally upgrading versions of Samba Active Directory does not require the purchasing of additional licensing, so further IT Department costs savings are realised.
If the example company had migrated from Windows Server Active Directory to Samba Active Directory, they would no longer be obligated to incur the cost of $93,990 CAD each time Samba Active Directory version updates occurred. Whereas if they stayed with Windows Server Active Directory and wanted to upgrade from Windows Server 2022 to 2025, they would be required to immediately incur the cost of $93,990 CAD as a non-optional license cost obligation, in addition to any growth in CALs they may need. And this obligatory cost would repeat each year-edition upgrade in the future.
This further demonstrates that over time migrating from Windows Server Active Directory to Samba Active Directory has substantial compounding IT Department costs savings.
Active Directory DALs
Some businesses have use-cases for Device Access Licenses in addition to CALs as they make more sense for those use-cases. An example is a kiosk computer on a factory floor, that is used by a large team of staff, whereby that particular set of staff frequently log into a singular kiosk computer as part of their duties. In that case a DAL for that kiosk computer is lower cost than getting a CAL for each of those particular staff. This is typically a lower cost item, but does add up to the picture.
The licensing costs for DALs are generally similar to CALs. They can cost around $100 CAD each, and each time the example company were to upgrade their Windows Server year-edition they would be obligated to re-purchase DALs for the new year-edition. If a factory floor has 20 Kiosk Computers with equivalent DALs, that would be approximately $2,000 CAD in costs that would need to be re-purchased when upgrading to a new Windows Server year-edition.
In-contrast, just like CALs, Samba Active Directory has no DALs whatsoever. Again this is if the environment only uses Samba for Active Directory and is not mixing with Windows Server for Active Directory. And this example further adds to the Total Cost of Ownership savings migrating from Windows Server Active Directory to Samba Active Directory realises for IT Departments.
💰 Ready to Eliminate Microsoft CAL & DAL Licensing Fees Entirely?
Transitioning to Samba Active Directory provides critical feature parity for domain controllers without user or device licensing taxes.
See How LANified! IT Services Deploys & Manages Samba AD for Canadian Businesses.
DHCP Server Licensing
We at LANified! IT Services have also encountered DHCP Servers installed and running on Windows Server Active Directory Domain Controllers. On the surface this may appear to be benign from a licensing perspective, however this is a frequently misunderstood and unaccounted for licensing cost obligation that's quite insidious and substantial. The harsh reality is that for every single IP Address a DHCP Server issues (when running on a Windows Server Active Directory Domain Controller) a corresponding CAL must be owned to match that IP Address provided by the DHCP Server. It does not matter what kind of device the IP Address is for, a CAL is needed for each one. This can lead to significant licensing cost obligations. As with so many other things, Samba Active Directory does not have licensing obligation costs for DHCP Server functionality. Let's explore some numbers on this matter.
Let's take our earlier example company of 1,000 staff. Consider the following:
- Each staff member likely has at least one cellphone (some staff might have more than one for functionality reasons). It is highly probable they are connected to the corporate network via the wireless network, and if the Windows Server Active Directory Domain Controllers are running all DHCP Services, that means all of these cellphones now require an additonal 1,000 CALs to be purchased.
- In addition to staff cellphones, there are other devices on the network. There are guest devices such as laptops, cellphones, tablets, and other devices that connect to the network and need an IP Address. In this case let's say the total of guest devices (as in used by humans who are not staff) are about 200 in count. Now a further 200 CALs must be purchased.
- There are likely going to be other legitimate company devices on the network that also need IP Addresses, that you guessed it, also need CALs. Desk phones, IP Cameras for security, meeting room equipment, servers, laptops, workstations, and so much more. For this example company this total count could be in the realm of 2,000 IP Addresses, and in turn, an additional 2,000 CALs that need to be purchased.
- If we add this all up, with the earlier defined price per CAL of $93.99, and a relevant IP Address count of now about 3,200 IP Addresses served by the Windows Server Active Directory Domain Controller's DHCP Server, we now have a license cost obligation of $300,768 CAD.
- Keep in mind that this is a cost obligation that has a high chance of going un-tracked. An audit by Microsoft may back-date license obligation charges so this could be even more.
- Further consider that CALs are tied to year-editions of Windows Server. So when example company needs to upgrade from Windows Server 2022 to 2025 for their Active Directory Domain Controllers, they need to also rebuy all of their CALs for the DHCP Server IP Addresses, so that is another $300,768 CAD in addition to the CALs for the staff, the DALs for devices, and the Windows Server OS licensing costs. All of this is to become license compliant.
So let's review the example company's licensing cost obligations across all 4 of these aspects. This example company has the following cost obligations (assuming zero company size growth) when upgrading their Windows Server Active Directory Domain Controllers from year-edition 2022 to 2025:
- Windows Server OS Licensing: $16,568 CAD
- AD CALs: $93,990 CAD
- AD DALs: $2,000 CAD
- DHCP Server Licensing: $300,768 CAD
Total: $413,326
This cost happens every time they upgrade to a new year-edition of Windows Server for this whole scope.
If this example company had instead migrated to Samba Active Directory, they would be saving $413,326 immediately in licensing cost obligations, and no longer need to incur the same cost obligation repeatedly in the future. And this does not include other cost savings we will outline below.
Hardware Requirements
Windows (desktop) and Windows Server are known for inefficient usage of hardware resources compared to Samba and Linux (which Samba would be running on) by a substantial margin. While this is less direct to convert into IT Department costs compared to licensing costs, the differences are impactful and measurable.
Taking our example company from above, each Windows Server Active Directory Domain Controller (including the remote office sites) would probably have IT Hardware Resource allocation along these lines (probably each being a Virtual Machine):
- CPU: 8x Cores
- RAM: 16GB
- Disk: 1TB / 1,000GB (justified for network shares content such as SYSVOL and others, but we find most companies massively over-provision network share storage)
Multiply this by 8x (the number of Windows Server AD Domain Controllers we explained earlier) and that turns into a rough total of:
- CPU: 64x Cores
- RAM: 128GB
- Disk: 8TB / 8,000GB
If the example company migrated from Windows Server Active Directory to Samba Active Directory, and kept the same number of Domain Controllers, the numbers would shift drastically.
- Note: We at LANified! IT Services would typically work with example company to migrate all network share data not related to Active Directory off of all AD Domain Controllers onto other IT Systems. It is commonplace for companies to put lots of unrelated content on their AD Domain Controllers, which cause security, scalability, and other IT Department problems. Migrating this data solves these problems, and also drastically reduces the footprint of each AD Domain Controller, in addition to Samba AD IT Resource savings. The below numbers take this data migration into account relative to the above Windows Disk uage.
Each Samba AD Domain Controller would probably be sized along these lines:
- CPU: 4x Cores
- RAM: 1.5GB
- Disk: 10GB
Multiply this by 8x (the number of total Samba AD Domain Controllers expected) and that turns into a rough total of:
- CPU: 32x Cores
- RAM: 12GB
- Disk: 80GB
If example company were to migrate from Windows Server Active Directory to Samba Active Directory, they would reduce their relevant IT Hardware utilisation by:
- CPU: 50% Reduction
- RAM: 91% Reduction
- Disk: 99% Reduction
We recognise that these numbers are prone to variability from one company to the next, especially the amount of Disk usage. However we also have found that these numbers are often not far from reality. By migrating from Windows Server Active Directory to Samba Active Directory example company saves substantial IT Hardware usage, which can be re-allocated to other purposes. Also note that these shifts in IT Hardware usage do not result in reduction in performance or functionality. Samba AD and Linux is simply that much more efficient than Windows (desktop) and Windows Server.
Maintenance
IT Departments can realise further costs savings in the difference of Maintenance between Windows Server Active Directory and Samba Active Directory. The cost savings are less tied to dollars saved and more to reliability and fewer hours spent maintaining Samba Active Directory and the Linux OS underneath.
Windows (desktop and Server) have specific noteworthy areas that are commonly problematic for maintenance:
- Windows Updates are buggy, unreliable, take far too much time to complete, have to reboot many times, and too often have to roll back for hard to identify reasons. This can at times lead to updates failing to such a degree that the "best" path forward is to just rebuild the whole Windows installation from scratch instead of fixing the system itself.
- Windows Updates typically have to be done after hours due to the above reasons, and this increases maintenance costs through higher IT Staff compensation, as well as making scheduling of such updating a lot more work than it should be.
- Fixing other complex Windows problems typically takes a lot of time to correct. This is due to a combination of multiple considerations such as inadequate documentation from Microsoft, unhelpful community forums that repeat the same non-functional commands regardless of the actual problem, commands to fix components of Windows that don't actually fix what they're supposed to (such as Snapshots or Windows Recovery), and much more. IT Staff burn a lot more time than they should just trying to make Windows do what it is supposed to, and this complexity is more pronounced in Windows Server and Windows Server Active Directory.
In contrast Samba Active Directory and Linux OS' (such as Ubuntu) have drastically lower maintenance costs involved. Which typically looks like:
- Ubuntu and Samba updates take minutes (instead of hours) to apply, are extremely reliable to apply, and are rigorously tested for stability. In the rare occasion of an update having a problem, fixing the matter typically takes a short period of time (usually minutes) and is expected to be successful, never requiring an entire system be rebuilt from scratch.
- Updates to Ubuntu and Samba are so fast and reliable, it is completely safe to execute them during operational hours. Rebooting an Ubuntu Server running Samba Active Directory typically can be done in under 30 seconds, even after applying all available updates.
- For other Linux/Ubuntu Server or Samba Active Directory problems, they typically can be corrected in a much shorter period of time, often in minutes. Quality documentation is easy to find, relevant community help resources are rigorously peer-reviewed and high in quality, commands and methods shared are typically very effective and reliable, and so much more. IT Staff (or us, LANified! IT Services) burn very little time solving problems related to Linux/Ubuntu Server or Samba Active Directory.
There can still be circumstances where correcting a problem with Linux/Ubuntu Server or Samba Active Directory can take a good bit of time. But in our experience these are the exceptions, not the norms. For day to day Maintenance we at LANified! IT Services have found that Windows typically has significantly higher Maintenance costs incurred by IT Departments than Linux/Ubuntu Server or Samba Active Directory. Furthermore we have observed that migrating clients from Windows Server Active Directory to Samba Active Directory has drastically reduced their repeated problematic IT Maintenance tasks related to those same Windows Server Active Directory systems, that would have normally burned away many IT Staff daytime hours as well as after hours and on-call hours.
Summary Conclusion
When we work with anyone that is interested in migrating from Windows Server Active Directory to Samba Active Directory, we first focus on the technical feasibility of it. There are legitimate scenarios where it does not make sense to migrate to Samba Active Directory. The reason this is the first thing we explore is because of how much confidence we have in Samba Active Directory in providing significant value in costs savings and other areas.
As we have outlined above, the savings are significant in IT Department money spent, IT Staff time spent, and so much more; these savings compounding even moreso over time. If we genuinely believe Samba Active Directory makes sense for one of our clients, we always are so excited for them to discover how much easier it is to actually work with, & how fewer problems they will have. It often shifts from "Oh our Windows Server is broken yet again" to "Oh I forgot the last time we had a problem with our Ubuntu/Samba AD Server". We at LANified! IT Services take pride in working with reliable technologies, and building rock-solid IT Systems. We prefer to sleep at night, instead of taking calls about some random Windows system that broke yet again at a time nobody wants to be awake.
If you find that you want to sleep better at night and explore the feasibility of migrating your own Active Directory ecosystem to Samba Active Directory, we highly recommend that you fill out the form below and we start having a great conversation. We look forward to hearing from you.
🔄 Seamless Windows AD to Samba AD Migration
We handle complete identity migration, GPO translation, and hybrid Entra ID (Azure AD) syncing with zero user downtime.
Fill out the form below and let's book a Samba AD Feasibility & TCO Audit.
.