Being able to use the protocol is one then. Configuration management and enforcement is something else altogether. Ever try to apply Windows domain group policy to a Mac? What kind of tools are there for the centralized management of that kind of hetrogenous OS environment that will scale to several thousand workstations?
Windows domain group policy doesn’t always work on *Windows* machines, for that matter. It certainly doesn’t work on Linux boxes.
And there *are* tools for centralized management of Mac OS X machines that do scale. However, they aren’t able to manage Windows machines any better than AD can manage a Mac. Likewise with Linux.
All it means is that your IT personnel have to actually earn those salaries. :D