So counter point. Active directory is a god send for managing endpoints, user accounts, endpoints, etc.
No you don’t let windows act as a dns server outside the ad subdomain, no you don’t use windows to admin your root private ca, and for all you hold dear do not enable that God forsaken web server. But for what it does well, it’s the best solution out there.
Enterprise tooling (aka a usable API) and it stays out if my way.