If Windows didn't turn into a shit-show post-Windows 7 I would prefer Active Directory over all of this mess. Log in once with your password or smartcard and that auth magically works across all applications without ever seeing a login screen or dozens of redirects to do the SAML flow, at least for internal tools. For external stuff, SAML/OIDC is kind of a necessary evil I think (I'm not sure if there's anything preventing external tools from interoperating with Kerberos).
Modern Windows has great improvements at the kernel level and OS internals but both the UI and general direction of the product (more focused on media consumption, services and the “attention economy”) is a massive downgrade.