Jump to content

Recommended Posts

Posted

Quick question - is there a way I can restrict logins on our Macs (which use AD authentication) to certain AD groups?

 

I use this quite a lot in windows, but haven't seen a way in Macs yet. I thought Access Control would be it, but it doesn't seem to do what I'm after.

Posted
There is a setting that allows you to select the groups/individual users you want to allow access to the machines. Give me a few minutes and I will upload a screen dump of the location.
Posted

If you wish to lock down a single machine you can do it using the local system preferences. click on system prefs, then User accounts and then login option. You will see a tick box that allows you to allow network users. If you then click on options it should list all the users and groups both from the AD and OD.

Local machine lock down.png

 

You can also do it via the WGM. I think this is what you are looking at now since you mentioned access control lists. I've not done it using WGM so not entirely sure if there are problems or not.

 

But from the looks of it the process should be something like this:

 

Create a Computer group and then add the computers you want to restrict to the group. Once done go to the preferences section and then login and then access. Click on the + icon to the left of the box. You should then see the a screen like the one below.

Networked Machine lockdown..png

 

When the drawer of users pops open to the left (or right depending on how much screen is available) look at the top of this drawer. You can see a small blue globe. Click on this and choose your AD from the list. You should then see all of your AD users/groups. Once these are available you should be able to drag them into the box, allowing them access to the machines in the group.

 

I hope this helps. As i say I've never needed to do this through WGM so not sure how well it works.

Posted
Cheers for that, thats exactly what I've done - added some AD groups into that list but in the WGM, but it seems to let anyone log in regardless. I might try it on the local computer just to see if that works.
Posted
Try using OD groups and see if that makes any difference. I've experienced issues where WGM does not apply settings to AD groups for some reason. I've gotten around this by nesting an AD group in an OD group, then using the OD group for preference management.
Posted (edited)

Hmm tried OD and AD groups in the WGM and it lets any user login. I'll try the local setting and see what it does.

 

 

EDIT: It seems our Macs just can't understand AD groups. If I set the preferences at the the WGM (using either AD or OD groups) it lets anyone login. if I set the preferences at the individual Macs (again using either AD or OD) groups it then doesn't let anyone log in!

 

if I specify individual AD users at the individual Macs then it works, but thats not a useful option for me

Edited by GoldenWonder
Posted

I have just tested this out with my own machine and user account.

 

I added my machine to a Computer list in the OD and configured this computer list for restricted access. I have 2 AD groups in the list. 1 is a group for all pupils and the other a group for all staff. The only user not in these groups is mine. Upon restarting the client machine (to pick up the new managed preferences) I tried my sons account (he's in reception), the login window shook. I then proceeded to try my login and logged in fine. I tried another staff users login whose details I can remember, and they could not log in. So the restrictions are working fine.

 

However, if I added my user to the all staff group, I could no longer login. But if I removed my account from the group again, I still could NOT log in. Only when I restart the client does the removal from an account take effect.

 

The Settings I used are Deny on the access for both groups.

 

There may be a conflict of group membership causing the issue. I don't know. What I do know though is that the restricted network access does seem to work.

 

Sorry if that's no help to you.

Posted
Hmm sounds like I have to Deny access, and then allow to selected users. However I don't think this will work as I want to deny access to students in general, but allow access to a specific set of students. But as they are members of students groups in general this might not work, as the Deny for 'all students' would include them!
Posted

The first thing I would do is get a restriction working. Once you can confirm there are no issues with regards to the restrictions taking place, you can send start to plan the process. If it were meI would perhaps look at creating a dedicated group in the OD or AD and join these users that are to be allowed access to these machines. Then add this group to the list.

 

I never tried using the Allow option. I can give it a go if you want to see what happens.

 

Deny takes precedence over Allow according to WGM.

Posted

Thats sort of what I'm trying to do. According to the documentation, if you add groups to the Access control list, only those groups that are explicitly allowed can log in. So I created 3 groups in OD, which contain AD groups of Staff,students and admins who are allowed to login. Result is still anyone can login! I'll try some deny settings but thats not how its supposed to work when reading Apples documentation.

 

The AD group for student only contains a dozen users (which is linked to the OD group) and the Staff/Admins contains the single overall group for each. Because, as you say, Deny take precedence I wanted to create and Allow only whitelist type of restriction.

Posted
One step forward, two steps back! I bound the Macs to OD and they then immediately started to pick up the access control policy, but it also mean the allowed users got no preferences (empy dock apart from finder etc) so I don't know what happened there!
Posted

It's strange that you say this as I have had a similar thing happen here. It is also very random. I just logged the user out and then back in and it sorts itself out. Very odd as this never happened on 10.5.x.

 

There was also a user where he had the same dock settings no matter how he logged in. I found this to be down to group membership. He was not in the group of users that had the dock preference assigned to that group, thus not getting the preference setting. Once I had added him to the right group he immediately started picking up the settings accordingly.

Posted

Mine seems to be consistent. When the Macs are bound to OD and AD, the machine prefs apply, the AD user can login but they get no prefs (just Finder!). When the Macs are bound only to AD and the OD server is specified users can login and get their correct prefs but the Mac gets no prefs at all!

 

When the Macs are bound to OD, they appear in the 'local' computers in WGM (as opposed to finding them in AD) so I assume this is the right way to go, but something is obviously not right. Do the Macs need to be bound to OD to get their prefs, or can I use their AD accounts (in an OD group) to apply prefs?

Posted

Well I've reached a sort of solution. Binding the Macs to OD and AD, and putting the OD server first in the Search order, then specifing the OD account name in the WGM seems to make the Macs pick up their Computer preferences. And it also seems to enable the access control. However the access control in OS X obviously can't copy with multiple group membership or it doesn't allow whitelist only type of restrictions. For example, if I only allow a certain group of students (who are also part of a large 'All' students group) then they can login,but end up with no Dock.

 

So if anyone else is having problems - bind to OD, ignore Apples instructions as whitelists on Access Control simply don't work!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...