Despite all of its flaws, Active Directory is the king. Jeff's advice is exactly what I have been preaching for a long time now:
I know this isn’t pleasant to hear, but AD is the incumbent. It’s nearly everywhere. It’s scalable to millions of users. The LDAP protocol is efficient and mature. It’s supported by countless applications. Before a customer considers displacing or adding another identity layer on top of AD they are going to need real cost savings or additional capabilities and order of magnitude over what they have now.
Let's all get with the program.
Microsoft, Active Directory, identity management