Hi
Play with this :
https://docs.saltstack.com/en/latest/ref/states/all/salt.states.win_lgpo.html
If you have windows minions and set it to run every 30/60/90 mins, and BAM you have AD without MS BS
While you can use salt grains to target OSes, I like to diffrentiate them with good naming system:
WIN.001
LIN.001
SRV.001
You might ask how to differentiate between windows SRV and Linux SRV, well frankly my dear i dont give damn, and i dont run Windows servers.