FreeIPA. Not a one off.
Right now I know that ipa doesn't work with Samba 4.8. This is causing me pain because now I have several one offs, because I have to use Winbind/SSSD to use Samba.
I currently manage 300+ boxes, with IDM ( FreeIPA ). I like to get SuSE into the mix, but unless it works with IPA, we are going to have to use Debian. I have ready no *buntu ( I don't care what anyone says, LTS isn't Enterprise ), because I need stable.
Once I have everything, service accounts, user accounts, and other things working. It's very nice and easy to manage.