Netwrix 1Secure delivers unified visibility across data and identity - free for 14 days with full access. Start a free trial

Resource centerBlog
Active Directory isn't going away. Your group policy setup might be as brittle as COBOL

Active Directory isn't going away. Your group policy setup might be as brittle as COBOL

Aug 11, 2026

A Reddit thread on r/activedirectory asking whether Active Directory is going away pulled in loads of comments, and the most upvoted answer compared AD to COBOL: still running, still critical, still not going anywhere. That comparison holds up when you check whether COBOL is still used today, since it runs core banking and government systems decades after its supposed retirement. The real risk for most IT teams isn't AD disappearing. It's that the group policy layer built on top of it has grown just as brittle as the legacy code everyone jokes about, with sprawling GPOs, no versioning, and change management held together by tribal knowledge.

AD isn't dying

A recent Reddit thread in r/activedirectory asked a simple question: is Active Directory going away? The post pulled in dozens of comments within hours, and one line summed up the debate better than anything else in the thread: "AD will go away like COBOL went away... (checks notes)."

It got over 30 upvotes for a reason. Everyone in that thread already knew the punchline.

Is COBOL still used? Yes, and that's the point

People have predicted COBOL's death for decades, and it's still running core systems at banks, insurers, and government agencies worldwide. It didn't survive because it's good. It survived because ripping it out is riskier and more expensive than maintaining it, and because there are too many dependencies wrapped around it to unwind cleanly.

Active Directory is following the same script: too many dependencies, too many administrators who've built their careers on it, too many applications that still don't support anything else.

None of that means AD is healthy. It means it's entrenched, the same way COBOL is entrenched. And entrenched systems accumulate the kind of technical debt nobody budgets for until it breaks.

The Active Directory going away debate is a distraction

AD isn't going anywhere in the timeframe that matters for your next audit, your next incident response, or your next compliance review.

The better question is what's been layered on top of AD while everyone waited for it to die. For most organizations, that's group policy: hundreds of GPOs added over a decade, half of them undocumented, some of them contradicting each other, and almost none of them built with modern hybrid or remote endpoints in mind.

That's the brittleness that bites. Not AD itself, but the policy sprawl sitting on top of it.

Group policy has the same problem as legacy code

Native Group Policy wasn't designed for the environments most IT teams manage now: remote employees, non-domain devices, Mac endpoints mixed in with Windows, and cloud-managed infrastructure sitting alongside on-prem servers. So teams patch around the gaps with scripts, workarounds, and one-off GPOs that nobody fully documents.

That's exactly how COBOL systems get fragile. Not because the original code was bad, but because thirty years of patches, workarounds, and undocumented exceptions pile up until nobody trusts changing anything.

What that sprawl costs you

Nobody notices GPO sprawl until they need to move fast. An audit asks which policy controls which setting, and nobody has a clean answer. A new hybrid or remote-work initiative needs policy enforcement on devices that were never joined to the domain, and the existing GPOs simply don't reach them. Someone touches an old GPO to fix one thing and breaks three others, because the dependencies were never documented in the first place.

That's the same failure mode as any aging codebase. The system still runs, right up until someone needs to change it under pressure, and then every undocumented shortcut becomes a production incident.

What to do about it

Start treating your group policy environment like the legacy system it's quietly become, and start cleaning it up before an audit or a migration forces the issue.

Netwrix PolicyPak was built for this. It consolidates sprawling GPOs to cut down on the noise and improve performance, and it extends policy control beyond what native Group Policy and MDM can do on their own. For teams moving toward hybrid or cloud-managed environments, it also transitions on-prem GPOs into MDM and cloud-managed setups, and it supports SaaS-based policy management for devices that aren't even joined to the domain.

Whether your org keeps AD for another two years or another twenty, the policy layer sitting on top of it needs to work across on-prem, hybrid, and remote endpoints today, not in some future migration that may never fully happen.

AD will probably outlive most of the predictions in that Reddit thread, just like COBOL outlived every article written about its death. The organizations that come out ahead won't be the ones who guessed right about the timeline. They'll be the ones who modernized their policy management while everyone else argued about it.

Netwrix PolicyPak

Modern endpoint management software for the Anywhere Workforce. Secure and manage Windows and macOS endpoints wherever your users work.

Download free trial

Share on

Learn More

About the author

Asset Not Found

Dan Piazza

Manager of Product Management

Dan Piazza is a Manager of Product Management at Netwrix, responsible for multiple Endpoint, DSPM, and Directory products. He has worked in technical roles since 2013, with a passion for cybersecurity, data protection, automation, and code. Prior to his current role he worked as a Product Manager and Systems Engineer for a data storage software company, managing and implementing both software and hardware B2B solutions.