Alternatives to FreeIPA

Open-source identity management for Linux users and hosts, combining LDAP, Kerberos, DNS and certificates. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as FreeIPA.

  • Univention Corporate Server

    A Linux-based server system providing open-source identity and access management for on-premises networks.

    Univention Corporate Server is a full Linux server OS for on-premises identity management, shipped as VM images and aimed at schools, public bodies and companies.

  • Samba

    Open-source SMB file and print server that can also run as an Active Directory domain controller.

    Samba can run as an Active Directory domain controller on Linux, also serving files and printers, though AD role configuration can be complex.

  • Zentyal

    An Ubuntu-based Linux server with Active Directory compatibility, mail and network services for small offices.

    Zentyal is a paid Ubuntu-based server with an Active Directory compatible domain controller, mail and network services for small offices.

  • Kanidm

    An open-source identity management server offering OAuth2, LDAP and passkey login from one place.

    Kanidm is a lighter open-source identity server offering OAuth2, LDAP, passkeys and Unix login integration, with a smaller ecosystem.

  • JumpCloud

    A cloud directory platform for managing user identities, access and devices across several operating systems.

    JumpCloud is a paid hosted directory with identity and device management, SSO, MFA and RADIUS, removing the need to run your own servers.

  • Microsoft Entra ID

    Microsoft's cloud identity and access management service, formerly Azure Active Directory, with single sign-on support.

    PaidProprietaryWeb

    Microsoft Entra ID is a paid cloud directory with single sign-on, removing self-hosting but tying identity to Microsoft's platform.

  • OpenLDAP

    Open-source implementation of LDAP, with a directory server, a load balancer, client libraries and tools.

    OpenLDAP is a standards-based open-source LDAP server without Kerberos, DNS or certificates integrated, and with no graphical management interface.

Also worth comparing

These listings name FreeIPA as their own alternative, so the relationship runs both ways.

  • 389 Directory Server

    An open-source LDAP directory server for Linux with multi-supplier replication.

    FreeIPA wraps an LDAP directory with Kerberos, DNS and certificates plus a web UI and Active Directory trusts, at the cost of a heavier deployment.

  • LLDAP

    A lightweight LDAP server for managing users and groups through a simple web interface.

    FreeIPA combines LDAP with Kerberos, DNS and certificates and supports Active Directory trusts, but is much heavier to deploy and operate than LLDAP.

Similar software

Related functionality, not a direct replacement.