Jump to content

Recommended Posts

Posted

I have set up a test mac network to role out Mavericks to our mac's eventually. We currently use Mountain Lion across school integrated with Active Directory to provide single sign on.

 

Anyway I am setting up the test Mavericks server and client in the same way but instead of using Workgroup Manager as we have in the past, I thought I would look at using the Profile Manager instead. I have got my head around how it works I think and have enrolled the client mac and installed the trust certificate for the server. The part that I am struggling with at the moment is that I have configured settings for our students user group. When I log in as a student they don't get the settings. It looks like the profile isn't getting pushed and applied when the student logs on.

 

Is there a guide somewhere or can anybody help me in the way they have Profile Manager set up or how to get a user groups profile to apply when they log on.

 

Thanks

Posted

Check both of the following:

- Ports - The link here has all of the ports that need to be opened in your firewall for Profile Manager to work.

- DNS - Common sense, but if this isn't right, you'll never have it right.

Others?

  • 4 weeks later...
Posted

Did you manage to get this working ?

 

All our machines will be binded to AD and OD

 

My test mac can apply Policys to the computer , but any AD user or AD group and the policy doesnt even get sent from profile manager ?

 

ports are all open on the server and on the client to negate any of these issues but it just wont even attempt to push to any AD user/Group even though i have enable it to do so ! .

Posted
May be a stupid question, but are the students logging in as local users or are the computers bound to the OD?

 

Is this in responce to my question ?

 

The client machines are both bounded to AD and OD .

 

The users login with AD usernames/passwords .. But no policy seems to get pushed to them ?

 

Computers seem to work fine ;)

Posted (edited)

It was. I normally try to ask the obvious questions first, but sometimes, I get accused of being thick, LOL.

 

Did you install the trust profile to the client devices (if you are not using a CA signed cert.) along with the enrollment and remote management profiles?

 

If so, then I also assume that you went into the Profile Manager web page (servername.domain.suffix/profilemanager) and assigned your settings to the group there, right?

 

Is this in responce to my question ?

 

The client machines are both bounded to AD and OD .

 

The users login with AD usernames/passwords .. But no policy seems to get pushed to them ?

 

Computers seem to work fine ;)

Edited by Jwzg
Posted

Thanks for getting back to me Jwzg

 

Yes i did all the above , and everything works perfect with opendirectory accounts and applying policys to the PC .

 

Just seems AD users it wont work on :( . I really dont understand the issue !

  • 2 weeks later...
Posted

If you haven't already you need to create Open Directory groups in Profile Manager then nest Active Directory groups within that.

 

Beware of Profile Manager though it's resource hungry and it does not scale well. Don't deploy more then 50-100 clients with or you'll be in my shoes with nearly 1700 macs and it takes ages to load or even push settings on a Mac Mini Server with 16gb of ram. You need something more robust like Puppet, Casper or plain old MCX if you want better scalability.

Posted
If you haven't already you need to create Open Directory groups in Profile Manager then nest Active Directory groups within that.

 

Beware of Profile Manager though it's resource hungry and it does not scale well. Don't deploy more then 50-100 clients with or you'll be in my shoes with nearly 1700 macs and it takes ages to load or even push settings on a Mac Mini Server with 16gb of ram. You need something more robust like Puppet, Casper or plain old MCX if you want better scalability.

 

Thanks for the tip, Steve.

 

As for us, we have over 400 devices and users running off of our MacMini server with 16GB of RAM, and although it can be a little laggy, it's not that bad. We use it for Profile Manager, update caching and OD (no other file sharing though).

  • 1 month later...
Posted

Still having this problem with Profile manager

 

I tried the above suggestion , created a OD user group and nested a AD user group inside . Profile manager doesnt even attempt to send to it :(

 

That being said WGM , works fine when i put a AD user account in a OD group and i can control the dock etc with that ! ??

 

Any more suggestions please :D

Posted

Profile Manager uses Apple push notifications ( like a iOS device) via apples servers the client to fetch new settings. You need some ports open to the OSX server to Apple's IP range and from the OSX client to apple's IP range.

 

Also nested groups only works in 10.9.2 (I think) and server 3.1. So if using older version of 10.9 start by running all updates and installing latest version of server.

Posted
Still having this problem with Profile manager

 

I tried the above suggestion , created a OD user group and nested a AD user group inside . Profile manager doesnt even attempt to send to it :(

 

That being said WGM , works fine when i put a AD user account in a OD group and i can control the dock etc with that ! ??

 

Any more suggestions please :D

 

I would suggest the same as MicrodigitUK and check that push notifications can be received in our environment. This link >> Push Diagnostics will help you easily confirm that. Hopefully it's available on the UK Mac App Store.

 

I wish you luck Profile Manager for me is a bear to keep running smoothly. It's very cranky most days. The last several weeks we've been having internet issues and it's not been fun, active tasks that pile up into the thousands, no pushes and it takes several refreshes to actually load the administration portal. I'm dumping it for Puppet or localmcx or another MDM provider.

Posted

 

Is there a guide somewhere or can anybody help me in the way they have Profile Manager set up or how to get a user groups profile to apply when they log on.

 

Thanks

 

There is a good guide for this on Krypted.com - Using Profile Manager 3 In Mavericks Server | Krypted

 

- - - Updated - - -

 

 

Is there a guide somewhere or can anybody help me in the way they have Profile Manager set up or how to get a user groups profile to apply when they log on.

 

Thanks

 

There is a good guide for this on Krypted.com - http://krypted.com/mac-os-x/using-profile-manager-3-in-mavericks-server/

Posted
I would suggest the same as MicrodigitUK and check that push notifications can be received in our environment. This link >> Push Diagnostics will help you easily confirm that. Hopefully it's available on the UK Mac App Store.

 

I wish you luck Profile Manager for me is a bear to keep running smoothly. It's very cranky most days. The last several weeks we've been having internet issues and it's not been fun, active tasks that pile up into the thousands, no pushes and it takes several refreshes to actually load the administration portal. I'm dumping it for Puppet or localmcx or another MDM provider.

 

Thanks for the program , says our PUSH notifications were ok

 

Seems our problem was NOT us . Turns out the New Mac Server APP 3.1.1 build that was released a few days ago has now fixed ALL our problems and we are now deploying to AD users and Groups

 

Thanks all for your help ;)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...