> Trying to administrate a large number of Windows machines without Active
> Directory controller support is like trying to ride a bicycle with no
> wheels, no crank, no sprockets, no chain, and a spike for a seat..
> Using Samba 4 utilities and this feature a administrator on the Samba box
> should be able to run a virus scanner or other such thing to check the
> registry settings of any system that is a member of the domain.
I think we are looking at this from slightly different angles. I was talking about enterprises where they definitely have AD DCs in production for administrating their thousands of Windows systems and users, and they do run virus scanners and much more with Windows/AD tools. But Samba 3.x nicely allows providing the aforementioned SSO services in those enterprise environments already today.
Wrt Samba DC in those environments, apart from organizational issues (like convincing AD admin teams and CIO to investigate and invest to Samba DCs), you'd also need to check with your Microsoft account manager what would happen support-wise to your Windows/AD systems if you'd add Samba DCs to an existing AD domain.