Jump to content

How to create an OS X Default Profile/Template & Bind to AD - 10.5 - 10.8


Recommended Posts

Posted (edited)

If you have any questions feel free to leave a note on this forum or email me at: [email protected]

 

 

 

This article will explain how to create a default user profile/template for OS X 10.6 Snow Leopard & OS X 10.5 Leopard as well a quick overview of how to bind your Mac to AD (Active Directory).

 

Included is a AutorMator script that cuts out a tremendous amount of time with preparing an image for deployment.

 

 

 

Why create a Default profile/template?

If you a computer that multiple users log into it on a regular basis & you want all users to have an identical profile with looks, setting etc. then this article will show you how to do so.

 

Binding to AD (Active Directory)

With the new version of OS X Snow Leopard, Apple has now moved where the Directory Utility is found. It's now part of core services unlike OS X Leopard where it was found in the Utilities folder.

 

 

Step 1 (Create default user profile/template ** OS X Snow Leopard & Leopard)

 

With your “admin” user fully update OS X.

** Keep in mind that there are some applications out there that will not run or support past certain version of an OS X. If this does not apply then update to latest OS X version release.

 

With your “admin” user install all needed applications that will be needed all check for any updates for those applications.

 

From the “Accounts” panel create a new user. (For this document I will create a user named “default”)

 

Enable “Root” user:

 

Snow Leopard 10.6 - Go to the Accounts Panel -> Login Options -> Network Account Server & select “Join”. Next select “Open Directory Utility”.

Once you have the “Directory Open” select ”Edit” from menu bar & select “Enable Root User” and give it a password.

 

If you chose to the direct method to open “Directory Utility” is /System/Library/CoreServices/Directory\ Utility.app

 

Leopard 10.5 - Go to /Applications/Utilities/Directory\ Utility.app

Once you have the “Directory Open” select ”Edit” from menu bar & select “Enable Root User” and give it a password.

 

Logout & then login into “default” user

 

Organize the Dock with all your needed applications

 

Adjust settings & preferences for:

 

Dock

Desktop/Finder/MenuBar

System Preferences (Run through each option in System Preferences & adjust as needed)

 

Run “ALL” applications that will be used on the system. Once each application has launched open it’s preferences and adjust as needed. (In most cases, it’s recommended to turn “off” “check for updates” if you do not want users getting prompted each time an application releases an update)

 

Once you feel happy with your image and everything is set the way you want it, continue to step 2.

 

Edited by Dos_Box
  • Thanks 4
Posted

Step 3(Binding to AD / Active Directory ** OS X Snow Leopard & Leopard)

 

 

Snow Leopard 10.6 - Go to the Accounts Panel -> Login Options -> Network Account Server & select “Join”. Next select “Open Directory Utility”.

If you chose to the direct method to open “Directory Utility” is /System/Library/CoreServices/Directory\ Utility.app

 

Leopard 10.5 - Go to /Applications/Utilities/Directory\ Utility.app

 

Once Directory Utility is open double click “Active Directory”

 

Once open enter in the needed info for your Domain, name computer & select what options you want or don’t want.

 

Now simply select “Bind” and enter in a user/password that has Network Administrator access to your domain.

 

You are now bound to your domain.

 

It’s also a good idea to change the login window to “Name & Password” if there will be many users logging into the computer.

 

Now restart your computer.

 

Once restarted & sitting at your login window, the best way to know you are connect to your domain is to click 5 Times where you see your computer name. You should see a colored dot, which will give you your status. You want to see Green.

 

Now try logging in using an AD/Active Directory account.

 

Enjoy :troll:

 

  • Thanks 2
Posted (edited)

Here is a quick video on what my "default_profile" script does when it is run. This script does a lot for cleaning up the profile, copying all needed files, correcting permissions etc.

 

 

Edited by Carter
  • Thanks 4
  • 2 weeks later...
Posted

Hello,

 

The application you created looks like it is right up my alley, however when i run it (as root) I get a:

 

" The action "Run Shell Script" encountered an error. Check the action's properties and try running the workflow again."

 

 

Do you have any suggestions? I am running this on an iMac running 10.6.6

 

thanks

DK

Posted
Hello,

 

The application you created looks like it is right up my alley, however when i run it (as root) I get a:

 

" The action "Run Shell Script" encountered an error. Check the action's properties and try running the workflow again."

 

 

Do you have any suggestions? I am running this on an iMac running 10.6.6

 

thanks

DK

 

Are you trying to run the script via terminal with a normal administrator or do you have the "root" user enabled to log into to run this?

 

I'm going to adjust this script to run under any user but haven't had the time to sit down to figure out how to prompt for admin password.

 

Posted
Are you trying to run the script via terminal with a normal administrator or do you have the "root" user enabled to log into to run this?

 

I'm going to adjust this script to run under any user but haven't had the time to sit down to figure out how to prompt for admin password.

 

 

Hello there.

 

I have a root user enabled. I logged in from the login window using the root user, I have also tried the terminal...and get this error:

 

admins-iMac:Desktop root# cd TwistedMac_default_profile\ 2.app/Contents/MacOS/

admins-iMac:TwistedMac_default_profile 2.app root# ls

admins-iMac:MacOS root# ls

Application Stub

admins-iMac:MacOS root# ./Application\ Stub

2011-03-28 20:30:33.937 Application Stub[203:903] No application name for definition file at path: /Library/Automator/Office.definition

2011-03-28 20:30:41.305 Application Stub[203:903] Automator Launcher is missing or damaged

 

any help is greatly appreciated.

 

Thanks

Posted

Odd..... not sure what's up with that. Try opening up AutoMator then open up the script. Here you should see all the steps and commands to be used in this script. If it opens here try re-saving the file.

 

Posted

Hi Carter,

No luck with that either...it opened up just fine in Automator, and I saw all the commands. I saved it as an app just fine but running it same thing.

Posted

Not sure why your getting those messages ... your running by just double clicking it right? I'll have a look tomorrow at the script to see if for some reason it's corrupt. used it today myself at work and was fine but will have another look tomorrow once back in the office.

 

Posted

Hi Carter,

I got this to work, however....

 

When an LDAP user logins into the computer they get prompted with "The System was Unable to unlock your Keychain" .....any ideas?

 

I have gone into the "default" user and deleted the Keychain, restarted and ran your script again. The keychain error is still present.

 

thanks for any help

  • 2 weeks later...
Posted

Hi all. Sorry to jump in here.

 

I don't need to set up a default profile as such. But I have a simple need to add one other user, - but copy the same profile as the administrator's to use for that user. I only want to do this once and I thought that OS X might just have a simple way of doing this, - but I can't find one.

 

Any ideas?

 

TIA

Posted

Hey Guys,

 

I have created my default template in a similar fashion as described above, however, I would like to be able to have my users choose which language they want and use the default template associated with that language, however, when I remove the AppleSetupDone it defaults to English without asking, so the other language templates are redundant.

 

Any ideas?

  • 3 months later...
Posted
Does this work for Login Items under accounts? For instance I a have a script that maps the userfolder from AD to the desktop. Having been able to get it to run when it's setup in the default profile. Doesn't seem to work for the desktop background either. I'm logging in with an AD account.
Posted
I can give this a quick try in a few mins here if you don't mind me trying the script. At least that way I can let you know? Just let me know.
Posted

You'll just need to change the server. It's still not even setting the desktop background either.

 

delay 10

set strUserName to do shell script "whoami"

set strFileServer to "net222.net.ucf.edu/userfolders$"

set strMount to "smb://" & strFileServer & "/" & strUserName

mount volume strMount

Posted

I'll give it a test but one thing I should mention or ask .... do you plan to have people saving files to this share? It's easy to open files from the share but if someone creates a new file they cannot browse the share? They will see the server and not the actually mounted share unless you have something else in place. I've tried and wanted to do this for a few years but Mac OS X only puts the server in the finder which then makes it harder for users as they then need to browse, well at least hear they have to browse through 100's and 100's of folders (they can't access them, just their own) but a nightmare to scroll and find their folder/share.

 

:cool:

  • 1 month later...
Posted
I've already joined our entire Mac Lab to our Active Directory, but have not set up the profile template yet. Will I have to unjoin before doing that or can I still do the profile work after joining to AD?
Posted
I've already joined our entire Mac Lab to our Active Directory, but have not set up the profile template yet. Will I have to unjoin before doing that or can I still do the profile work after joining to AD?

 

Upi can leave them bound but you will need to trash the home folders of those already logged in that you want to have the new folder. If not when they login they will get their old folder that they already had in place. new default profiles will only be created for new users.

  • 2 months later...
Posted

I just updated the script download links above & below. Please make note of the OS X Lion 10.7 script. This one has a small additional command to run which removes the files located in folder ~/Library/Application Support/Ubiquity/ "Ubiquity" is a name codename used for iCloud with Apple. This will not hurt anything as the folder contents will be re-created once the user goes to login. The script would not run because the contents in this folder could not be copied.

 

 

OS X Leopard 10.5 - OS X Snow Leopard 10.6 - http://dl.dropbox.com/u/121843/OSX10.5-10.6_default_profile.zip

OS X Lion 10.7 - http://dl.dropbox.com/u/121843/OSX_10.7_default_profile.zip

Posted

Concerning the mounting of AD student shares, I use a script that puts an alias of the user's folder, which is inside the share, on the desktop.

Our student shares are divided alphabetically, so a path for a student whose username starts with "h" would be

/volumes/studenth/hfacebookuser

 

Note that AD mounts the actual server so one doesn't have to use its actual name.

 

Here is the script :-

 

#!/bin/sh

 

me=$(logname)

x=$(echo $me | cut -c1)

/bin/ln -s /volumes/STUDENT$x/$me /Users/$me/Desktop/$me"'s H Drive"

  • Thanks 1
  • 3 months later...
Posted
Hi Carter,

I got this to work, however....

 

When an LDAP user logins into the computer they get prompted with "The System was Unable to unlock your Keychain" .....any ideas?

 

I have gone into the "default" user and deleted the Keychain, restarted and ran your script again. The keychain error is still present.

 

thanks for any help

 

Hi how did you get the script to work as Im getting the same error as you originally did when you first ran the Default script. Thank you

 

JC

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...