Active Directory/Kerberos user authentication best practices?
I am looking to evolve our database environments to use Active Directory authentication for individual users, with normal TNS connections for non-individual users. I know that Kerberos authentication used to be part of the ASO from Oracle but as of 11gR2 it is now part of the Oracle database. Has anyone followed a plan to move from password based accounts to AD authenticated accounts without ASO installed. If so, what are the steps to align with best practices in this area?