Jump to content

Recommended Posts

Posted

Hey guys,

 

I'm in the process of setting up our first set of Macs and I've hit a hurdle and I can't seem to find a clear answer (More likely can't phrase my question properly!) about the user accounts.

 

It seems like a good opportunity to set them in up a way which makes things "future proof", by that I mean what happens when (Not an if I'm afraid) and suddenly we've got staff switching to Macs, or we go to 1:1 scheme and students take them home over the summer (we're an international school so that could be anywhere in the world).

 

I've got JAMF Pro and ASM (Federated with AAD based on group membership) all setup and working as expected, user accounts in AAD appear in ASM. Now this is where my lack of experience with Macs comes in, my test user was created within on Prem Domain, added to the ASM group, that sync'd over to ASM and now my test user has an Apple ID. So I though at this point should be able to walk over to shiny new Mac and log in with the Apple ID and away we go. I then found out, that's not how it works...

 

All I'm finding is information about binding the on-prem domain, which isn't something I want to do. Remember the bit where I said about people working off site? I'd like to be in a position where I can get the devices delivered straight to the user without the need of having to come into the workplace to pick the device up and finish setup.

 

I'm also finding articles saying that binding to AAD isn't possible, so I then came across NoMAD, which turns out is now JAMF Connect. But the wording on JAMF connect makes it look as though it just sets up a local user account on the device that syncs with AAD. The JAMF reseller I've used was unable to tell me if that's what I need to achieve this "binding".

 

What I'm looking for is basically a way for these devices to be fully cloud managed (Through JAMF Pro) then all logins etc to be serviced by Azure AD... So how do I achieve this? (Or am I barking up the wrong tree)

Posted

Have you looked at jumpcloud?

They'll do you 10 devices for free...naturally it gets expensive but really thinking about this, I don't see any way of binding to AD other than some kind of SDWAN/MPLS style solution to provide on prem AD coverage at each site.

Posted

Yes, imho it does look like an open ldap in the cloud.

 

If these are student devices though..do you 'have' to have them on AD at all?

Posted

It'll be both students and staff using these devices.

 

I'd rather have the identities bound to something so that things like single sign on, file permissions and firewall authentication still work

 

On the other side, I want to be in a position where if we replace all staff surface pro's with macbooks, username/password combinations still work and they can just log into anything, from anywhere.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...