Jump to content

Mac Server, Windows Domain, AD etc...


Recommended Posts

Posted

Hi All,

 

Does anyone know a good place to start/have a link to a good guide for setting up a mac server on a windows domain? I would like to log into the mac with the users ad account & lock down the mac based on their ad user group if this is possible. I've just started looking at macs & I have no clue with them, so any help would be great.

 

Thanks

 

M

Posted
Hi All,

 

Does anyone know a good place to start/have a link to a good guide for setting up a mac server on a windows domain? I would like to log into the mac with the users ad account & lock down the mac based on their ad user group if this is possible. I've just started looking at macs & I have no clue with them, so any help would be great.

 

Thanks

 

M

 

There are a few ways you can go with this and what you do depends on how many Mac clients you will have, how much money you have to spend, and how much you want to learn about managing Macs.

 

If you have only either a few clients or more money than time to learn, then you can just use Centrify (http://www.centrify.com/directcontrol/mac_os_x.asp) or AdmitMac (http://www.thursby.com/products/admitmac.html) and manage the Macs pretty much just like you do your Windows clients using GPOs. You'll still need to create separate GPOs for the Macs, but it will be familiar and relatively painless. These solutions aren't cheap for large numbers of Macs though.

 

If you have more time than money, then you should use a Mac Mini server and WorkGroup Manager (WGM) or Profile Manager. If you use profiles then you just bind the Macs straight to the Domain Server for authentication and use profiles for management.

 

In between these two options cost-wise is Casper Suite, which can do everything from imaging, package deployment, policies, profiles and more. CS is like SCCM and a bit more for Macs. JAMF offers excellent pricing for Education on the licensing, but there is the upfront one time JumpStart.

 

Whatever you use for management (unless its CS), you'll still need an imaging tool, but you can use the built-in NetInstall service on a Mac Mini running the server app (http://support.apple.com/kb/HT5599) or the excellent and free DeployStudio (http://www.deploystudio.com/Home.html)

Posted
cheers seawolf, I appreciate your help, I've set up a mac server, and trying to use profile manager, problem is my ad users show up in users of the server app, however when trying to set up profile manager, only my local admin user shows up. If I log in to the profile manager web interface as my ad user, I get the option to enrol, if I click this it looks like it's doing something, then stays on the same page. Any ideas.
Posted
cheers seawolf, I appreciate your help, I've set up a mac server, and trying to use profile manager, problem is my ad users show up in users of the server app, however when trying to set up profile manager, only my local admin user shows up. If I log in to the profile manager web interface as my ad user, I get the option to enrol, if I click this it looks like it's doing something, then stays on the same page. Any ideas.

 

Make sure you've set it up as indicated here http://www.krypted.com/?p=7619

 

Krypted is a good source of info for many things Mac.

  • Thanks 2
Posted
I've managed to get this working & I can now enrol devices :) however no ad users show up in profile manager. I'm using Mountain lion server & the instructions from the site you posted are for lion...Can almost smell victory now.
Posted
I've managed to get this working & I can now enrol devices :) however no ad users show up in profile manager. I'm using Mountain lion server & the instructions from the site you posted are for lion...Can almost smell victory now.

 

You did bind the Mac server to the AD domain and you installed WGM for 10.8 and followed that part of the instructions? If its still not working I don't know. Without seeing it myself it could be a bit of the needle in a haystack.

Posted
Looks like I've cracked it, had to create a group and add users to it. Then they'd show up in profile manager, although I had to search for them before they would show. Have just set up profiles now & waiting for them to push. Hopefully all will work, then I can wait for September until the kids come back & break everything :)
Posted
Last bit, if anyone can shed any light. I'm trying to apply settings to ad users when the log in, so students & staff get locked down differently. However no profiles are being pushed out automatically, I've opened all the relevant ports for APN on the firewall, still no luck. HELP!!!!
Posted
Last bit, if anyone can shed any light. I'm trying to apply settings to ad users when the log in, so students & staff get locked down differently. However no profiles are being pushed out automatically, I've opened all the relevant ports for APN on the firewall, still no luck. HELP!!!!

 

Go to one of the client machines, open up terminal:

 

telnet gateway.push.apple.com 2195

 

If you get access, means it isnt being blocked.

Posted

I can get access when running that command. It shows up in profile manager when I log on to the machine: push settings username: studentuser - sending

 

however it doesn't seem to send.

Posted
Suppose I could lock them down with wgm, are there draw backs to this?

 

The only drawback is that WGM will probably disappear in 10.9, but the underlying MCX settings will likely still work. And with profiles users don't have to logout/in for changes to apply.

Posted
thanks, having trouble getting client macs to show in workgroup manager, they are bound to the OD & AD, they show in the AD section on workgroup manager but only the server shows in the OD part. If I try to add it manually it says there's already a mac with this name?! So confused.
Posted
thanks, having trouble getting client macs to show in workgroup manager, they are bound to the OD & AD, they show in the AD section on workgroup manager but only the server shows in the OD part. If I try to add it manually it says there's already a mac with this name?! So confused.

 

You have do do a secure bind of clients to OD when you have a magic triangle setup for computers to appear in WGM.

 

BTW - this is probably the most up to date instructions for setting up magic triangle I've seen lately - current as of 10.8.4

 

http://www.papercut.com/kb/Main/MacOSXMagicTriangle

Posted

Thanks again Seawolf, Happy days, I'm pretty much done with setting them up now, user logs in with AD account & the machines are locked down.

 

In order to get it to work properly I had to create a group in OD & import the ad groups/users, then set up my WGM preferences.

 

The next step is deploying a bunch of apps. Had a quick google & looks like I need to invest in ARD. Is there a way of deploying apps to the macs without this?

Posted
Thanks again Seawolf, Happy days, I'm pretty much done with setting them up now, user logs in with AD account & the machines are locked down.

 

In order to get it to work properly I had to create a group in OD & import the ad groups/users, then set up my WGM preferences.

 

The next step is deploying a bunch of apps. Had a quick google & looks like I need to invest in ARD. Is there a way of deploying apps to the macs without this?

 

ARD is well worth the (very small) investment and it can do far more than just deploy software packages. Highly recommended. You can also use DeployStudio to deploy packages (apps) and it makes a great free Mac imaging tool as well. It can do Mac only or dual and triple boot deployments as well.

Posted
Thanks again Seawolf, Happy days, I'm pretty much done with setting them up now, user logs in with AD account & the machines are locked down.

 

In order to get it to work properly I had to create a group in OD & import the ad groups/users, then set up my WGM preferences.

 

The next step is deploying a bunch of apps. Had a quick google & looks like I need to invest in ARD. Is there a way of deploying apps to the macs without this?

 

http://deploystudio.wikispaces.com/ - a good resource for all things DeployStudio.

 

The other free options out there are Munki (or Simian) and Puppet. I haven't tried these myself, but they have a good rep. Beyond these, Casper Suite can do just about anything you could want in managing Macs. Costs money, but reasonable for Edu.

  • Thanks 1
Posted
Cheers man, Getting into this now. I've managed to lock it down as much as i can, edited the sidebar plist & got rid of network/harddrives etc in finder, however when clicking the computer name you still get an option to browse the network, is there a way of killing this, can't seem to do it as an admin user either. arghh. I will defeat these macs, Seawolf i owe you many pints.
Posted
Cheers man, Getting into this now. I've managed to lock it down as much as i can, edited the sidebar plist & got rid of network/harddrives etc in finder, however when clicking the computer name you still get an option to browse the network, is there a way of killing this, can't seem to do it as an admin user either. arghh. I will defeat these macs, Seawolf i owe you many pints.

 

Sorry, I've never tried to kill the network browsing feature myself, so I'm not positive about this one. I can't find anything about removing this at afp548, krypted, etc. so I it doesn't look like it can be done, but I might be wrong. There is usually a way with plists and MCX, but there are some things Apple just wont let you change in the interface.

 

Do you not want students to be able to access network shares at all on the Macs? Normally, I wouldn't remove the network drives from the finder so the students could access the network shares. Just trying to understand the use case to make sure there isn't another way to achieve what you want.

Posted

Cheers guys, something to have a crack at this afternoon. What i've noticed too is that when saving a document the user can browse to the hard drive by clicking on the computer name. I only want them to be able to save to their home folder & nas box that we have. I know there will be a world of hurt when kids start saving stuff to the local drive then panic that the "network has deleted their work" when they don't see it in their home folder on another machine. Anyone know how to do this...There's lots of stuff on the web to do with running terminal commands, but don't fancy pasting these straight in without knowing what they are doing. Sure there will be some way to script hiding a drive on login. I'll be glad when these are done, i'll never curse group policy & active directory again.

 

Thanks again for all of your help with this. Has anyone done the ACSP training? How did you find it?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...