Gongalong Posted January 9, 2020 Posted January 9, 2020 Hi Folks, Is there anyone out there using MDM with Apple iMacs that isn’t using Jamf School/Zuludesk? We are really struggling to get LDAPS set up with it, and although I haven't given up yet it would be helpful to know what alternatives are out there. Basically all we need from MDM is: - It uses our AD accounts to logon to the iMac. - It can map drives to a Windows server. - if it can map a Windows printer and deploy software, even better. We’re only buying 16 iMacs, so won’t have vast numbers. Any recommendations? Thanks
FragglePete Posted January 9, 2020 Posted January 9, 2020 Mosyle. Not doing too much in depth with it, but it's looking after our small fleet of iPADs superbly but does allow MacOS as well. Pete 1
Brimstone Posted January 9, 2020 Posted January 9, 2020 Hi Folks, Is there anyone out there using MDM with Apple iMacs that isn’t using Jamf School/Zuludesk? We are really struggling to get LDAPS set up with it, and although I haven't given up yet it would be helpful to know what alternatives are out there. Basically all we need from MDM is: - It uses our AD accounts to logon to the iMac. - It can map drives to a Windows server. - if it can map a Windows printer and deploy software, even better. We’re only buying 16 iMacs, so won’t have vast numbers. Any recommendations? Thanks You haven't looked at the guide for this...? https://docs.jamf.com/jamf-school/deploy-guide-docs/Setting_Up_LDAP_Authentication_in_Jamf_School.html 1
DalekSec Posted January 9, 2020 Posted January 9, 2020 Another one for Mosyle, love it! Does everything you ask plus more. 1
Gongalong Posted January 9, 2020 Author Posted January 9, 2020 https://docs.jamf.com/jamf-school/deploy-guide-docs/Setting_Up_LDAP_Authentication_in_Jamf_School.html Certainly looked at something very similar, linked within Jamf's config page. The guide is a little out of date as Jamf only allow LDAPS, you can't use LDAP anymore. We just can't get the certificate bit sorted out on the DC, which needs to talk to Jamf. They talk about using the Certificate Authority role, which we can't get to work, but even then we've been advised that a bought certificate still needs to have a public facing name and .local name which you cannot do.
Brimstone Posted January 9, 2020 Posted January 9, 2020 @Gongalong Have a read through this thread in Jamf Nation about this issue with .local.. https://www.jamf.com/jamf-nation/discussions/31396/important-notice-regarding-jamf-infrastructure-manager-ldaps-and-jamf-pro-10-11 1
dhicks Posted January 9, 2020 Posted January 9, 2020 - It uses our AD accounts to logon to the iMac. - It can map drives to a Windows server. - if it can map a Windows printer and deploy software, even better. We went for the "Binding Computers To Active Directory" option: https://docs.jamf.com/jamf-school/deploy-guide-docs/Binding_Computers_to_Active_Directory_or_Open_Directory.html This was nice and easy to set up - pretty much a case of plug the appropriate details in and away we went. Looking at that documentation page, I've just seen the "Google Sign-In" option - is that new? I've tended to use a login script to get past any limitations with the settings available. We can deploy software via the App Store, or sometimes via a .PKG distributed via the MDM (although this tends to be variable), otherwise we deploy by having a login script check for the software and running a silent install if needed. We've also installed Homebrew, for packages (e.g. Python) that installs that way. 1
Gongalong Posted January 10, 2020 Author Posted January 10, 2020 @Brimstone Thanks, very useful! Then that suggests we're stuffed as far as using LDAP. I'll ping Jamf Support an email and see what they have to say. We went for the "Binding Computers To Active Directory" option I kept hearing bad things about binding to AD, that it was unreliable. But obviously not your experience? Is still possible with this to map network drives, much as with Windows? I've just seen the "Google Sign-In" option - is that new? We've only been trialling a couple of months, so not sure. I've tended to use a login script to get past any limitations with the settings available. We can deploy software via the App Store, or sometimes via a .PKG distributed via the MDM (although this tends to be variable), otherwise we deploy by having a login script check for the software and running a silent install if needed. We've also installed Homebrew, for packages (e.g. Python) that installs that way. I'll only need to deploy Logic Pro, which we're buying with VPP credits.
dhicks Posted January 10, 2020 Posted January 10, 2020 I kept hearing bad things about binding to AD, that it was unreliable. But obviously not your experience? We had a problem a couple of weeks after we'd first got set up where half-a-dozen Macs dropped off the domain. It was simple enough to fix, simply have them disjoin and rejoin the domain in the Mac OS settings. It turns out the Computer objects had disapeared from the Active Directory OU they should have been in - not sure why, if it was something to do with the Macs or something to do with our AD. We don't seem to have had a problem since, so it's not something I've investigated any further. Is still possible with this to map network drives, much as with Windows? Yes, although it's an all-or-nothing setup - you can either redirect a user's folder or not, you can't redirect folders inside that folder - so if you want to redirect to a network Documents folder (sensible) you also have to redirect the application data folder where things like iMovie store large files (not good if the whole class is doing video editing or similar). Our pupils don't use Windows machines now anyway, so we have the Macs mounting Google Drive instead.
Gongalong Posted January 13, 2020 Author Posted January 13, 2020 Trying the bind and getting an error (The ‘Directory Binding Account’ payload could not be installed. Attempts to bind to the server ‘redacted.redacted.redacted.local’ returned an unspecified problem.) I've logged it with Jamf support...
dhicks Posted January 13, 2020 Posted January 13, 2020 Trying the bind and getting an error (The ‘Directory Binding Account’ payload could not be installed. Attempts to bind to the server ‘redacted.redacted.redacted.local’ returned an unspecified problem.) Hmm. What version of Mac OS? We're on Mojave, which binds okay to Active Directory - and we're using a .local domain at the moment, too. Maybe more security restrictions if you're on Catalina (we haven't dared tried upgrading anything yet).
Gongalong Posted January 14, 2020 Author Posted January 14, 2020 It has Catalina. Jamf were unhelpful. Just said that the error is created by the Mac, and we need to speak to Apple!
Gongalong Posted January 14, 2020 Author Posted January 14, 2020 I've tried binding it manually to see if that allows the profile to carry on. Despite that though I can't logon with an AD account. I put in the details, the wheel spins below for a few seconds, then stops. No login, no error.
Gongalong Posted January 14, 2020 Author Posted January 14, 2020 Got binding to work. AD accounts seem to be a bit flakey - will not login at first (gives the shake), but will then login on a second attempt. I've now got an issue when logging in where it gives an error "A keychain cannot be found to store "BeaconStoreKey"." and the login won't progress past this. I'm asking Jamf if it's best just to flatten this test iMac and start again, as it hasn't been reinstalled since it was bought late 2013.
dhicks Posted January 14, 2020 Posted January 14, 2020 I'm asking Jamf if it's best just to flatten this test iMac and start again, as it hasn't been reinstalled since it was bought late 2013. Probably the best idea - we found wiping-and-reinstalling our iMacs to be very easy, with the Mac itself handling the reinstallation of the OS via the Internet (make sure you reformat the disk first, otherwise the OS will be re-installed but all the existing applications will stay in place). Upon rejoining a freshly-installed Mac to ZuluDesk it was recognised and had the appropriate policies applied straight away. 1
Gongalong Posted January 14, 2020 Author Posted January 14, 2020 If I choose option 1 from here, does it give the option to format? https://support.apple.com/en-gb/guide/mac-help/mchlp1599/mac
Gongalong Posted January 14, 2020 Author Posted January 14, 2020 I went ahead anyway, went into Disk Utility, and deleted the two partitions that were there. I didn't delete the System Image partition, but have chosen to install fresh from the Internet. It then wouldn't show me a partition to install to, so I had to go back to the Disk Utility and create a partition to install to. Not exactly intuitive, but it seems to be installing now...
dfergusson Posted February 11, 2020 Posted February 11, 2020 Got binding to work. AD accounts seem to be a bit flakey - will not login at first (gives the shake), but will then login on a second attempt. I've now got an issue when logging in where it gives an error "A keychain cannot be found to store "BeaconStoreKey"." and the login won't progress past this. I'm asking Jamf if it's best just to flatten this test iMac and start again, as it hasn't been reinstalled since it was bought late 2013. Did you get resolution to this issue?
Gongalong Posted February 11, 2020 Author Posted February 11, 2020 Jamf said I had to rollback to an earlier version of MacOS, which I just wasn't prepared to do - it meaning reinstalling 16 Macs, and what if it happened again?! I was curious to trial Mosyle anyway, so tried that and didn't get the issue. And although Jamf's support were good I started to get "shrug" answers from them, whereas Mosyle just seemed that bit better technically and always had suggestions. We're going ahead with Mosyle.
dfergusson Posted February 11, 2020 Posted February 11, 2020 What setup did you go with Mosyle and active directory?
Gongalong Posted February 11, 2020 Author Posted February 11, 2020 iMac is bound to the domain with a profile. Sorting out the profile was still a bit of a faff because of the field names used in the profile not actually being what the fields should have been populated with e.g. server hostname should actually be the domain name. Presumably that comes from Apple? I've had an issue twice where the iMac's domain record has seemingly gone "stale" and it needed to be re-bound. We don't actually use this in anger until Easter when we get 16 iMacs, so will see how stable it all is. Technically it seems a better solution to me to have the iMacs talk directly to the DC, rather than going some convoluted route. If the logon issues continue you can spend a couple more bucks per iMac and use a Mosyle app to login, which apparently still works with local ADs.
Carter Posted February 11, 2020 Posted February 11, 2020 Over the past year we've been in circles with what we will go with. JAMF though on the pricy side it's looking like it will be the most reliable solution to do everything we're looking for. WE have InTune and we're pushing that as an option but it's limited when it comes to full Mac Management.
Gongalong Posted February 12, 2020 Author Posted February 12, 2020 Depends which version of Jamf, bearing in mind they bought Zuludesk (now Jamf School) which is a cheaper option. Jamf School is very similar to Mosyle, in fact I prefer the interface, but it was the aforementioned issues that caused us to switch to Mosyle. Ultimately all they are doing is using Apple's profile management via the cloud.
Brimstone Posted February 20, 2020 Posted February 20, 2020 Ultimately all they are doing is using Apple's profile management via the cloud. This is totally incorrect, products like Jamf School have very basic tools for managing macOS it's really only deisgned for iOS devices, if you are using the cheapest version this comes with zero support. With Jamf Pro it provides a whole suite of Jamf specific configuration payloads and scripts, connectivity for identity creation via Azure or Google, SSO and many other tools for profile management for both macOS and iOS Seems to me you were trying to use the wrong solution.
Gongalong Posted February 20, 2020 Author Posted February 20, 2020 Jamf School had a ton of options for MacOS profile management, much as Mosyle does. The paid option comes with support, same with Mosyle. I agreed Jamf Pro is a much bigger product, but it also has a much bigger price tag and required training. We've done what we want with Mosyle, so not really a case of the wrong solution. Jamf Pro would have been a sledgehammer to crack a nut.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now