Jump to content

Recommended Posts

Posted

Hi All

 

I would like some information regarding the abode topic. I work in a school and the current setup is as below:

 

1. Windows Server 2008r2 as AD

2. Mac server El capt

3. Mac server connected to AD via binding

4. Mac server running all services including Open directory

5. Mac server ruining profile manager we can see all AD groups from windows server and user

 

The problem is with profile manager. We can set a local network user on the mac server and that person can log on to the iMac without a problem. We can also set a profile for that user via the profile manager on the mac server , for example stop them using the system tools which works. On examination this user he is in the open directory for users and groups and the default groups that are pushed to the user. this all fine.

 

The problem is when we log on to the system with are domain user we cant push any profile configuration to them we can set them but they don't work or apply. Please advise ?

Posted

When you enrolled the devices to the mac server did you use a local account or domain account to enroll them? I've had all sorts of issues with our setup but I've always used a domain admin account to login to the profile manager and also when enrolling the devices the same account is used.

 

Also do you use any sort of proxy at all which is based of the user accounts permissions since the profile manager needs access to specific URL's and ports so if domain users are hitting the proxy restrictions that could be another potential issue.

Posted

Hi

 

Thanks for your reply. When we set the Mac server and start open directory and profile manager we used a local admin account on the mac server that is the only account that logs us on to the profile manager. we can log on too the iMac that we have which a AD account but no profile are getting pushed out or applied to that user. Have we done something wrong on when we setup the mac server. Both the mac server and the iMac that we are using to test are connected top the mac open directory and the Windows Server 2008 r2 Active Directory. Any advice and help is welcomed and appreciated.

Posted

From the sounds of things your setup looks to be fine since your AD is connected and your server setup also sounds correct. We don't usually log into the mac server itself unless we need to check logs but we also use a local account when doing that since there isn't much point using an AD account for the server itself.

 

I would say the best bet is to contact Apple enterprise support since I've been in contact with them a huge amount due to issues with our setup and they will allow you to send them your server logs to take a look at and will advise you if there are any configuration issues. The odd thing in your case is that the deployment does work but only with local accounts so all I can suggest is going back to basics by re-installing one of the macs and then adding it to your mac server manually by downloading the trust profile etc from the device via safari.

 

I also recommend setting up a group on the mac server which has all the AD settings but nothing else so once the device has been added drop it into that device group and see what happens since if it works you know there's a setting somewhere that's causing domain users to not accept changes.

Posted

Hi

 

Thank you for your reply. Can you please advise on your last comment how " I also recommend setting up a group on the mac server which has all the AD settings" do you binding setting . please advice. Thank you

Posted

The way we setup our mac-server is so that once enrolled the device isn't part of any device groups but once you add the device to the domain group it pushes out the AD settings to each of the mac clients. Unfortunately we had to reset our mac server so currently I don't have any of the mac's on the server to show you but you should have something like this:

macserver.PNG

The Pupil Mac group would have all of the pupil restriction in however you would also create another group just for the AD connection as this will allow you to test to see if the profile pushes to the mac client and if it does you can then test further setting changes as a domain user.

Posted

Hi

 

Thank you for your help so far. We have created a group in the profile manager called "student mac" under devices as you have stated. The part we are getting problems is pushes out profile manager to AD user. You say we need to create another group for AD connection can please advise on how this process is done and how it would connect back to the AD from the mac server. Thank you for all your help so far it has started to put us in the right direction.

Posted

Basically both your mac clients and mac server need to be connected to AD as the only reason that the server is connected to AD is so that your able to apply restrictions and policies to AD users and groups when they are connected to clients. Also it allows the users to authenticate to the mac server as the server will know the user is an AD user rather than an open directory user.

 

So lets assume your set is as follows:

 

Mac Server Connected to AD with Open Directory Setup

Mac Client default install not connected to AD or Mac Server.

 

The first step would be to get the mac client enrolled to the server so you would visit the URL to your server from the client (https://YOURSERVER.local/mydevices/). Once on that page you need to select profiles at the top and then download the trust profile and install it to your mac as this will ensure the connection is trusted once the device is enrolled. Next go back to the devices page and enroll the device and once completed you should see the device appear on your server on the profile manager.

 

At this stage you need to start work on your profile manager so open up the web page (https://YOURSERVER.local/profilemanager/) and go to device groups. Create a new device group and select the settings tab for that group and then the edit button to start changing the group settings. Once opened scroll down until you see the OS X section of the restrictions as these will apply to your OS X devices and then select the Directory section under that group. Select the configure option and then in the drop down select 'Active Directory' which will adjust the page form allowing you to enter your domain credentials which will allow your mac's to connect to your AD environment but make sure they are correct and the OU is also set correctly as moving the devices manually afterwards in AD isn't advised since Mac's are flaky at best with AD.

 

Once setup select the okay button and then save the Device group. You can now add the device you have enrolled to this group and again save the group settings which will start a push of the profile to the enrolled device. This should deploy fairly quickly and create an active task within a few seconds so if this doesn't happen there will be either an issue with the server or there's an issue with the client communicating with the mac server. If it does work however you should find you can now log into the client with an AD user but you will need to try making another change to the group you created to see if the mac can accept changes even when logged in as a domain user.

 

I hope the above has enough detail, I hated setting up our Mac platform but I hope you don't have to suffer for as long as I did!

 

Regards,

Chris.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...