HMCTech Posted June 13, 2009 Posted June 13, 2009 We are thinking about putting half a dozen Mac's into our windows domain. I have read that I can join the macs to authenticate on active directory, get mapped drives so I wouldnt need a Mac server for users?? Also Would those macs be able to go out through our exsisting ISA server?? Would all a mac server be good for is locking down the Mac's?
Sylv3r Posted June 13, 2009 Posted June 13, 2009 I have looked into putting MACs on our windows network this year too. I am not an expert in this topic but I don't think you need a xserve etc for the AD integration - I however will probably use a mac mini as a server to deal with locking the MACs down.
HMCTech Posted June 13, 2009 Author Posted June 13, 2009 Was not looking at an xserve as they are too expensive also thought about a mini with the server OS installed.
robk Posted June 13, 2009 Posted June 13, 2009 We found that the mac os x server is needed for the apple equivelent of Group policy, you could get the macs to authenticate to the domain without, but with no control over the desktops etc. RobK
FN-GM Posted June 13, 2009 Posted June 13, 2009 As others have said, you only need the server to lock them down. As for ISA it wont be a problem at all.
jbiesta Posted June 17, 2009 Posted June 17, 2009 Yep, macs will now intergrate fine with active directory to authenticate users but to have 'group policy's on the mac to lock them down etc you will need a mac server. if you only have a small amount of macs you wish to integrate you can easily do the locking down with a mac mini running osx server which is a much cheaper option than an xserve and works just as well provided your only putting in a small number of macs.
maxshanly Posted June 17, 2009 Posted June 17, 2009 You do not need a Mac running OS 10 Server. I won't go into too much detail as I am a bit strapped for time but I'd suggest checking this article out as I found it very useful.
HMCTech Posted June 30, 2009 Author Posted June 30, 2009 You do not need a Mac running OS 10 Server. I won't go into too much detail as I am a bit strapped for time but I'd suggest checking this article out as I found it very useful. Thanks for this, I did try installing it on OS X but just get a huge amount of different errors when trying to do any task.
HodgeHi Posted June 30, 2009 Posted June 30, 2009 You could also extend the AD schema if you are that way inclined. This then allows you to use the WGM tools to configure your Policies for your users and OS X clients and save them directly into your AD Schema. This method is also free
DMcCoy Posted June 30, 2009 Posted June 30, 2009 You could also extend the AD schema if you are that way inclined. This then allows you to use the WGM tools to configure your Policies for your users and OS X clients and save them directly into your AD Schema. This method is also free There are some new whitepapers for this from apple and a very nice tutorial video. I will be attempting schema extension again soon. I've managed to get most things working in the past trials but not computer groups - now essential for 10.5, the new guides tell you how to create these groups in AD manually now.
HMCTech Posted July 1, 2009 Author Posted July 1, 2009 So in an ideal world what would be the best soulution? To bind a mac client to AD for authentication then extend the AD scheme to manage and lock down the client? Or to use AD for authentication then use an OS X Server to lock down the apple clients?
HodgeHi Posted July 1, 2009 Posted July 1, 2009 I think that depends on 2 things. 1, Most admins don't like extending schemas in case of any problems. I think that in Server 2000 schema changes were non-reversible so if you messed it up then you were stuck with the changes and they got replicated across the domain/forest. With server 2003 AD this is not the case and schema changes can be reversed. I'm sure i read that somewhere. So it depends on how comfortable with this you are. 2, Cost. The AD schema extension doesn't cost a bean apart from your time, whereas the XServe does cost. It costs a fair bit. But what you do get is the ability to utilise some of the services that come with the server software. For example, if you currently do not have a mail server then you could utilise the mail service, which also has no CAL costs associated to it meaning as many accounts as you want. You maybe could utilise the Jabber service to provide your users with the ability to use IM internally and also keep a log of conversations, thus securing and adhering to policies. You may also wish to utilise the Apache service to host a shared calendar or even a wiki. The wiki server isn't the best version but it is indeed very simple to use. We went for the Xserve here as we could utilise most if not all of the services. Also you get the ability to netboot/netinstall. If you have quite a few machines or are looking to expand on the number of macs you have then this could be very useful.
DMcCoy Posted July 1, 2009 Posted July 1, 2009 (edited) So in an ideal world what would be the best soulution? To bind a mac client to AD for authentication then extend the AD scheme to manage and lock down the client? Or to use AD for authentication then use an OS X Server to lock down the apple clients? At the moment we do the second, if the extensions can be convinced to work this time we will use AD for both (the xml prefs will be stored in AD the same way as OD). The only thing we need os x server for would be the disk imaging. Edited July 1, 2009 by DMcCoy
HodgeHi Posted July 1, 2009 Posted July 1, 2009 There are some new whitepapers for this from apple and a very nice tutorial video. I will be attempting schema extension again soon. I've managed to get most things working in the past trials but not computer groups - now essential for 10.5, the new guides tell you how to create these groups in AD manually now. Do you have any links to these? I would be greatly interested on how it has developed since the last time i saw.
HMCTech Posted July 1, 2009 Author Posted July 1, 2009 I think that depends on 2 things. We went for the Xserve here as we could utilise most if not all of the services. The xserver would be an unneccesary cost for us with only 16 machines so we are going to do what others have suggested and buy a mac mini and put the server OS onto that.
HodgeHi Posted July 1, 2009 Posted July 1, 2009 My mac mini and OS X Server at home has been solid now for over a year
binky Posted July 1, 2009 Posted July 1, 2009 No you don't, you can just extend your ad schema to accomodate the extra mac options!
DMcCoy Posted July 1, 2009 Posted July 1, 2009 Do you have any links to these? I would be greatly interested on how it has developed since the last time i saw. Apple - Seminars Online - Modifying Active Directory Schema to Support Mac Computers It tells you to sign up for access to the white papers, although this is only for US people. Simply google the white paper names to locate them on the apple site anyway, all 3 are there. Watch the video too, it's very informative. Don't need the special scripts from apple any more, it seems, just using ADAM from Microsoft and some manual editing. 1
PRicho Posted July 1, 2009 Posted July 1, 2009 We've just got a Mac Mini and OSX Server to do exactly this with 26 macs. Not had chance to play with it yet, managed to get OSX installed on it but only via the upgrade option, couldn't boot from the CD. Let me know how you get on!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now