speckytecky Posted December 17, 2009 Posted December 17, 2009 Our Art room has 3 MAC workstations and a MACBOOK which the teacher would like joined to our Windows 2008 Domain. Never been near MACs before so I was wondering if there are any guides someone could point me toward please.
3s-gtech Posted December 17, 2009 Posted December 17, 2009 Top of this forum is a sticky, I used this and it was spot on. Some problems reported with 10.6 (Snow Leopard) though. 1
cookie_monster Posted December 17, 2009 Posted December 17, 2009 I'm no MAC expert but i've seen a few threads and know a school that use a Mac mini as an OSX server apparently this can then have a trust with active directory. As the Macs then use the OSX server it all works more smoothly. 1
K.C.Leblanc Posted December 17, 2009 Posted December 17, 2009 It's doable, but you can't join them to the domain and lock them down without either using 3rd party software or having a Mac server (it can any sort of mac). 1
sted Posted December 17, 2009 Posted December 17, 2009 in a nutshell (more detailed versions are on here or i can post if needed) modify the ad schema s the apples have somewhere to store their settings. Set ad to index mac addresses. install workgroup manager on a mac (personally i set up a mac with all software including this and clone it using carbon copy cloner so they are all the same) use directory util on the mac and add it to the domain and make domain admins local admins. play round with workgroup manager till its locked as you want it 1
iSteve Posted January 6, 2010 Posted January 6, 2010 You can join your Macs to your Windows 2008 domain (which is what we do), by going in to Directory Utility --> Services --> Active Directory and 'binding' them in there, which is the same as what you do on Windows when you join. From here your Mac machines will log in to your Windows domain, and depending on your set up, mount a home folder and so forth. If you want to lock the Macs down Group Policy style, you need a Mac running OS X Server. This comes with Workgroup Manager, which is like GPO for Macs. Any crappy old Mac from the last 8 years could cope with this task providing it meets the requirements for whatever version of OS X Server you wish to install. 2
sted Posted January 7, 2010 Posted January 7, 2010 You can join your Macs to your Windows 2008 domain (which is what we do), by going in to Directory Utility --> Services --> Active Directory and 'binding' them in there, which is the same as what you do on Windows when you join. From here your Mac machines will log in to your Windows domain, and depending on your set up, mount a home folder and so forth. If you want to lock the Macs down Group Policy style, you need a Mac running OS X Server. This comes with Workgroup Manager, which is like GPO for Macs. Any crappy old Mac from the last 8 years could cope with this task providing it meets the requirements for whatever version of OS X Server you wish to install. you dont need a mac server workgroup manager works on osx workstation you just need to make the appropriate schema changes to ad
Rozzer Posted January 7, 2010 Posted January 7, 2010 I have a website with a few resources. HowToMac.co.uk | Bringing the future of Apple into education Hope it helps. Ross 1
Robbocop Posted January 8, 2010 Posted January 8, 2010 Good info on this thread already, so just to agree that you can bind your Macs to AD easily, and depending on what groups are using them that might do the job - ie if you don't need client lock down. If you want to lock them down you would either need an XServe or a Mac running as a server (with a licence for OSX Server software), or you can buy licences (one per client Mac required) for Centrify Active Directory Integration for Mac OS X which allows you to set Mac permissions for Mac clients directly on the windows server without changing your schema. The other thing you might want to investigate in Extreme Z-IP PC to Mac Issues? | Try Extreme-ZIP | Group Logic which allows the Windows server to talk to the Macs in their native AFP file format. This is quicker, and gets rid of the double files normally generated by the Macs. Both can be downloaded as trials and both are really good. 1
sted Posted January 8, 2010 Posted January 8, 2010 Good info on this thread already, so just to agree that you can bind your Macs to AD easily, and depending on what groups are using them that might do the job - ie if you don't need client lock down. If you want to lock them down you would either need an XServe or a Mac running as a server (with a licence for OSX Server software), or you can buy licences (one per client Mac required) for Centrify Active Directory Integration for Mac OS X which allows you to set Mac permissions for Mac clients directly on the windows server without changing your schema. The other thing you might want to investigate in Extreme Z-IP PC to Mac Issues? | Try Extreme-ZIP | Group Logic which allows the Windows server to talk to the Macs in their native AFP file format. This is quicker, and gets rid of the double files normally generated by the Macs. Both can be downloaded as trials and both are really good. you DONT need a mac server you can lock them down from a normal mac quite happily if you modify the ad schema
Robbocop Posted January 8, 2010 Posted January 8, 2010 Sted: Agreed. However mostly we've found that people are reluctant to modify the schema. For a handful of Macs Centrify is really cheap. However, as it's a cost per client Mac, an XServe works out far cheaper on large numbers of Macs, and as XServes come with an unlimited SAL client count, you don't need to buy any more licences if you choose to add more Macs later. If you're happy to (or allowed to!) modify the schema, that's fine.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now