Apple's Macworld Looking To Corporate Users
coondoggie writes to mention a Network World article about a focus on corporate users at the upcoming MacWorld Expo. Along with the consumer announcements (iTV, iPod stuff), there will be several elements dedicated to introducing IT pros to Apple hardware. From the article: "The show has really evolved. For a long time it was a consumer-oriented show and those of us who are from the enterprise space - there weren't very many of us - would use it as a place to meet and compare notes ... Now Macintosh in the enterprise is becoming more recognized and there are tracks that are specifically for us enterprise people. We don't have to sneak off anymore."
AD Integration has been there for a number of years. You use the Directory Access application in /Applications/Utilities, and there's an AD tab where you enter the relevant information. It provides authentication and full single sign-on. You can also change the password on your Mac and it propagates to AD. So what's the issue?
You can also manage the Macs via AD, if you want to lock them down. This requires a schema extension -- extensions that Apple has registered with the IANA. This historically has made some AD administrators nervous, especially back in the day when you couldn't reverse schema additions. These days, the scripts are fairly widely available -- install them on a test or staging server and see how it works.
So this provides very good management, the main limitation at this point is it's necessary to use Apple's Workgroup Manager application to do the management of the Macs, and point it to AD. Most Windows administrators are used to using GPOs for management and are reluctant to use another tool. If this is too much of a hurdle (you know, that whole "learning new things" thing which may be scary to people whose brain filled up getting their MSCE certification), then look for 3rd party tools like Centrify's Direct Control (http://www.centrify.com) which allow you managemetn of the Macs totally via GPOs.
Pretty much any way you WANT to manage Macs from AD, you can. Each option has a few caveats, and is not 100% like using AD to manage Windows machines, because they are different machines. But all solutions WORK, and in fact they WORK QUITE WELL.
As far as MVL, it does apply to copies that run in Parallels. So you're covered there -- the expense is the copy of Parallels... which is $79 list, and I'm just betting if you asked them for 500 copies that they'd negotiate a bit.
Regarding Entourage... you're right, it's not as good as Outlook. But for many folks, it's sufficient. As far as Excel... I've never personally had an interop issue between Windows and Mac versions of Excel or Word. Then again, I'll freely admit I don't get many documents that are loaded down with large numbers of VBA macros. Whenever I get a "enable Macros?" dialog I say no -- so that point is moot anyway. With the main use of VBA being to transmit viruses... it's a wonder they're really still prevalent on the Windows side. And I say this having written a few custom decision support systems based in Excel and Access, that used custom OLE controls no less, back in the day.