joewb Posted March 2, 2020 Posted March 2, 2020 (edited) Hi All, Just making everyone aware of the changes Microsoft are implementing that will affect Mac devices if they are bound to AD. Microsoft have recently announced that they will depreciate the use of LDAP during a required security update in March 2020. This is to further to the Microsoft Advisory ADV190023 announced in August 2019. Full details of the recent update announcement can be found here. Microsoft will force all traffic over the more secure LDAPS protocol which by default will not be supported by your Apple Mac estate if they are bound to Active Directory. Edited March 2, 2020 by elsiegee40
3s-gtech Posted March 2, 2020 Posted March 2, 2020 Shouldn't the Apple guide be enough? https://support.apple.com/en-gb/guide/directory-utility/diru6d9bb70e/mac If you want Open Directory to use SSL for connections with the Active Directory server, select Encrypt using SSL. Before you select SSL, ask your Open Directory administrator if SSL is needed. If Directory Utility can’t contact the Active Directory server, you might need to adjust your configuration access settings. See Change connection settings for an LDAP or Open Directory server.
5tu Posted March 2, 2020 Posted March 2, 2020 (edited) Hi All, Just making everyone aware of the changes Microsoft are implementing that will affect Mac devices if they are bound to AD. Microsoft have recently announced that they will depreciate the use of LDAP during a required security update in March 2020. This is to further to the Microsoft Advisory ADV190023 announced in August 2019. Full details of the recent update announcement can be found here. Microsoft will force all traffic over the more secure LDAPS protocol which by default will not be supported by your Apple Mac estate if they are bound to Active Directory. Hi Joe Are you happy to outline the steps you've taken so that others can benefit? Many thanks Edited March 2, 2020 by elsiegee40 Moderator removed unauthorised commercial text
old_n07 Posted March 2, 2020 Posted March 2, 2020 Microsoft have also put the "required update" back to the second half of this year and the March updates will now contain updated logging settings to help users troubleshoot the move. https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/ldap-channel-binding-and-ldap-signing-requirements-march-2020/ba-p/921536/page/2
joewb Posted March 2, 2020 Author Posted March 2, 2020 Shouldn't the Apple guide be enough? https://support.apple.com/en-gb/guide/directory-utility/diru6d9bb70e/mac This is suitable for small amounts of devices as it requires manually installing and trusting certificates and then rebounding the devices, but this can be automated if you have a management system in place which is the suggested method for companies/schools with larger Mac estates. 1
free780 Posted March 2, 2020 Posted March 2, 2020 I already have the root CA cert on macs. I used a script to bind with SSL enabled. They no longer log as insecure LDAP binds. The LDAP change is probably not going to happen until June/July but more logging will be available after the March CU.
joewb Posted March 4, 2020 Author Posted March 4, 2020 I already have the root CA cert on macs. I used a script to bind with SSL enabled. They no longer log as insecure LDAP binds. The LDAP change is probably not going to happen until June/July but more logging will be available after the March CU. Yes, you are correct that Microsoft recently announced this has now changed, I'll update the original post if possible.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now