I can pontificate on the Linux vs. MS forever. You must understand and accept that on the DOS level MS has one user (root) and one group (root) with one permission (remove all). This is a major and very simple issue to comprehend. This is why any penetration into the system via RPC, HTTP, or any other protocol with ports below 1024 is catastrophic. You obviously can physically disconnect your system from the network, but it will be nonsensical action.
Second issue - Active Directory. You will be much better off if you will use OpenLDAP. Active Directory was implemented with a serious deviation from the canonical LDAP. And it's a shame. But MS needed it a lot to compensate somehow deficiency in ACL of DOS OS design.

I can go on and on. I am obviously very subjective in my opinion. But, I do have on my laptop two partitions, one for the Linux and the other NT. All my servers are Linux boxes. And I like this arrangement very much.