Jump to content

MAC Suite - integrated to AD but students see all shares on network?


Recommended Posts

Posted

Hi all,

 

Not the most experienced person in the world with MACs but in short.....

 

Engineer is configuring a suite of MACs with a mac mini server to setup a link between AD and OD, so that students and staff can login with their usual credentials and save to their My Documents and shared areas, and see the licence server for sibelius amongst other things.

 

However when a student logs in they are able to browse using finder and see every possible share on the network, although not access any folder or documents unless they have the correct permissions. They are able to see folders such as finance, personnel and various others.

 

The Engineer feels that it is because of the Bonjour (mDNSResponder) service but states he cannot turn it off or we will lose internet connectivity and other network services. There is no way to disable the view of the network, or prevent the students from seeing anything. On the windows network, they get the mapped drives we choose and that's it, is there no way on MACs to enforce such a policy?

 

I wondered if other schools could share how locked down their macs are, and if they have the same problem, and either live with it or there is a way to hide/disable them?

 

Any help would be greatly welcomed.

Posted

We use plists through Workgroup Manager to control Finder and run an Applescript at login to map the drives how we like. We prevent access to all the pre made folders (music, video, pictures, etc) as they map locally.

 

Our script maps the home folder to the "Documents" folder and hides/removes access to the rest. So all they see (and can save to) is the documents folder and any network shares.

 

I can send you the plists and script if you want?

Posted
We use plists through Workgroup Manager to control Finder and run an Applescript at login to map the drives how we like. We prevent access to all the pre made folders (music, video, pictures, etc) as they map locally.

 

Our script maps the home folder to the "Documents" folder and hides/removes access to the rest. So all they see (and can save to) is the documents folder and any network shares.

 

I can send you the plists and script if you want?

Thanks for the information @ben604 thats really useful - ill PM you my email. Thanks.

  • 2 weeks later...
Posted

Hello Ben604/Max power

This issue came up today for me when playing around with our Imacs on our domain......is here a way of doing this without running it on a mac server? We have about 15 macs and no server at the moment...

Thanks

Posted

Hello,

 

you can probably do it machine to machine, but it'll be laborious. I'd get a Mac Mini or another iMac to run Workgroup Manager/Profile Manager.

Posted
This is mostly likely due to the way Mac interpret hidden shares on NTFS, with Windows the $ sign indicates that the share is not to be visible in the list of shared folders. However a MAC seems to think the $ donates the end of the share path and won't look any further beyond that. The best way round this is to enable access based enumeration on the root of the users share and make sure your NTFS permissions are set accordingly.
  • Thanks 1
  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...