I am the author of Foxpass. It was designed to solve exactly these pain-points with its cloud-hosted LDAP and RADIUS systems. Plus it ties into Google Apps, which many companies use as their de-facto root identity. Foxpass plus a SAML provider (i.e.) Okta is a great way to really close to single-sign-on everywhere (internally and externally), without running the services yourself.
I am the author of Foxpass. It was designed to solve exactly these pain-points with its cloud-hosted LDAP and RADIUS systems. Plus it ties into Google Apps, which many companies use as their de-facto root identity. Foxpass plus a SAML provider (i.e.) Okta is a great way to really close to single-sign-on everywhere (internally and externally), without running the services yourself.