Google Apps for email, works miracles and it still allows you to use Outlook but also lets you use all the nifty free Mac apps. It has a calendar and automagically blocks spam. I've set this up for about 15 domains now, everybody loves it.
Active Directory however is one of the best features of Windows in the enterprise. Sure, their permissions make me go cross eyed but that's another story and has nothing to do with AD. It's really just LDAP with extensions anyway so you are complaining about the Microsoftisms that drive everybody nuts. It's a hard job to design a tool that works 90% for everybody in every use and not have some limitations from doing that.
As has been said previously: the flaw here is a PEBKAC issue. To save them from themselves we should be asking M$ to port Office to the Wii and a large majority of users can use that. The real issue that drives us all nuts with Windows is that it is a platform for 3rd party apps that work like shit. Almost all the M$ programs I've had to admin work awesome on their own, it's that accounting app that is 23 years old or some one-off utility database that sucks balls and forces us to reach around our heads to scratch our ear.