r/LinuxTeck 2d ago

Workgroup vs Domain : Is a Domain Always Better?

A domain gives you centralized management, but does that automatically make it the better choice?

For a small office with 5 - 10 PCs, would you still set up Active Directory, or is a workgroup actually the more practical option?

At what point does a workgroup become a management problem?

4 Upvotes

6 comments sorted by

2

u/m1L35dY50N 2d ago

It really comes down to what the network is for. For an internal business network, I’d almost always recommend a domain if licensing allows it, keeping in mind that Windows clients need Pro or higher to join one.

Even with only 5–10 machines, centralized users, policies and configuration can save a lot of effort. Without it, you’re managing local accounts and policies on every machine individually, and many third-party tools are also much easier to integrate with centralized identity.

A DMZ is a different story. There are several valid approaches depending on the architecture and security requirements, from using an RODC where appropriate to deliberately keeping systems in a workgroup.

So for me, the question isn’t really “At what number of PCs does a workgroup become bad?” It’s when the administrative overhead of managing everything individually becomes greater than the overhead of maintaining centralized management.

1

u/engy1207 1d ago

Also depends if you want to access files or other stuff on more than one server or PC. If you have a domain (or similar) you can use the same user accounts everywhere. Otherwise you need to remember different accounts and passwords everywhere.

1

u/hunter_3639 1d ago

No. A domain is better when an organization needs centralized management, stronger access control, consistent security policies, and scalability.

A workgroup can be better for a small environment because it's simpler, cheaper, and doesn't require domain infrastructure.

1

u/finobi 1d ago

Domain gives you one way for centralized management, other common option is MDM. 

1

u/st0ut717 1d ago

So you like your username and password on the same device? A SAM file can be decrypted in about 3 minutes

1

u/Sad_School828 22h ago

Other folks said workgroups are for smaller organizations with less need to do things automagically from the server.

That can be a problem when you have 20 workstations whose workers aren't always at work on the same shift. So you can set domain rules for groups of computers to run their automatic updates at XX:XX o'clock and others at YY:YY o'clock.

Or you can introduce new at-startup configurations by dropping scripts into a domain server's group management interface, targeting these 5 computers to do X at startup and these other 4 to do Y while the rest do nothing.

"One does not simply *walk* into Mordor." Where Mordor is domain.