Jump to content

Recommended Posts

Posted

We have a Mac Mini running El Capitan Apple OS X server. I have deployed 6 iMacs using the server... with 21 more to come.

Currently, I'm using Open Directory on the mac Mini. E.g. Mac users have a separate login to their AD Creds... not ideal.

I know you are able to join Macs to AD but I also want to be able to manage them using profile manager (so I can lock down system prefs and other things people might maliciously tamper with).

 

I've read about the 'golden triangle' where AD handles auth and OD does profile provisioning but I'm slightly confused. How do the Active Directory users and groups actually get into the Profile manager website interface. Is there some kind of import/sync process.

 

Also - how would I go about redirecting the home folders to the users home folder on the windows network. E.g. \\server1\users\john.doe ? I want users to be able to access their files from the Macs

 

I use a Mac personally but have only got my simple OS X Server setup. Active Directory integration is a whole new ball game for me.

 

Cheers!

Posted
I know you are able to join Macs to AD but I also want to be able to manage them using profile manager (so I can lock down system prefs and other things people might maliciously tamper with).

 

I bind macs to AD then use the enrolment profile to enrol them to profile manager (so that they can be locked down). When setting up restrictions, I'd create an open directory group then add the AD group as a member of the OD group (assigning the restrictions to the OD group rather than the AD group) as I don't think you can assign restrictions directly to AD groups.

 

I've read about the 'golden triangle' where AD handles auth and OD does profile provisioning but I'm slightly confused. How do the Active Directory users and groups actually get into the Profile manager website interface. Is there some kind of import/sync process.

 

As above, I bind the macs to AD rather than OD (and when looking into this I seemed to get the impression that the golden/magic triangle was for older (10.6 & below) OSX versions). Joining the mac server to the AD domain should make the AD users/groups appear in profile manager.

 

Also - how would I go about redirecting the home folders to the users home folder on the windows network. E.g. \\server1\users\john.doe ? I want users to be able to access their files from the Macs

 

Can't really help with this one but there is an option in one of the PM restrictions (login items?) to add an icon in the dock for a network home drive (pulled from AD)

  • 2 weeks later...
Posted (edited)

To redirect home folders you need to set the AD binding settings as below. You don't need to bind clients to the Open Directory but you do need to enrol them into Profile Manager. I'm not actually sure of the nuance there but there you go.

http://i.imgur.com/XsKXfMG.png

 

You can use AD groups in Profile Manager (I do). Bind your server to the AD (using directory utility) and they will be available to you in profile manager.

 

Side note:If you're deploying multiple machines I'd look into Deploy Studio. Took me a while to start using it but it's great. Also get Apple Remote Desktop

Edited by furby

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...