So you want a corporate directory, but you don't have a corporate budget. You want to reap the benefits of single sign-on, the ease of administration for yourself and the ease of use for your users.
why arent you considering something centralized like FreeIPA? i run a manually-integrated "de-constructed" directory services suite of Kerberos, SASL, LDAP and SSSD, where i manage users and dont have ...