andyire Posted December 9, 2016 Posted December 9, 2016 We updated our macs recently to El Captain and have been having various issues. Our Macs are bound to AD and to a Mac server with their home folders being served from a Windows Server. I have just discovered Account Unknown(S-1-5-88-3-448) ACL is being added to the users home folders when they are created and it is stopping them accessing their documents / movies folders etc. Has anybody come across this ? Any advice would be much appreciated
3s-gtech Posted December 9, 2016 Posted December 9, 2016 Have you seen this? https://welsheduit.wordpress.com/2014/11/07/os-x-10-10-yosemite-and-ad-home-directories-via-smb-fixed/
andyire Posted December 9, 2016 Author Posted December 9, 2016 Hi 3s-gtec, thanks for your reply. Just had a look at that article, unfortunately its not a fix for us. Cheers
jhothersall Posted December 9, 2016 Posted December 9, 2016 I get the same thing, give a repair libary. We think office 2011 does this but I could be wrong ..
HodgeHi Posted December 9, 2016 Posted December 9, 2016 The issue generally plagues new user accounts as it adds an everyone deny POSIX permission to each individual folder when the Mac creates the account on the server. It just doesn't work like it used to under 10.6.8 and has been broken since 10.9. You could try to fix the issue by removing the ACLs and then reapplying them properly but be warned that the Macs don't always have ACLs propagated down the structure properly either these days. What I mean by this is you could manually create a folder in the Documents folder stored on the server and it will only create the POSIX details. This means that the inherited perms don't get applied. I have been trying to find a way to resolve this issue properly for some time now. Forced Local Homes are the best way forward for now until A, Apple fix it properly or B, Users get used to working locally and manually shift important data to the server for backing up.
andyire Posted December 14, 2016 Author Posted December 14, 2016 Hi All, I have been in touch with Apple Enterprise support today who say they will investigate and potentially escalate. I am not too confident , but if a fix is provided I will post it here. If no fix is provided, I think I will create a scheduled task on the file server to run a script with icacls command to remove the everyone group from the ACL 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now