Jump to content

Locking down OSX clients in AD domain


Recommended Posts

Posted

We've had 20 eMacs for a couple of years and recently got Remote Desktop and OS X Server.

 

I can bind the Macs to the AD so that domain users can log in with their usual username and password and get their windows home-directory.

 

Previously, when the eMacs where standalone, I locked them down nicely locally.

 

However now, all AD users get a generic apple desktop.

 

How can I lock-down the desktop, software etc. and make it apply to sets of AD users for all of our Macs?

Posted

Define "Lock Down"

 

There's a method for distributing a standard OS and APP install for OS X on my website (http://rhymeswithgeek.com) and also a method of creating an account 'template' that gets applied to users the first time they login to populate the dock, etc, in the way you desire.

 

At the end of the day though, If you want proper network orientated control of the desktops on all your macs, give different groups of users different options based on group membership, etc, you'll need to buy a Mac server and use the tools available in that to integrate into AD and to use the results of that to determine available resources on the Macs.

 

I wouldn't say it was a difficult task as such, but it requires some investment in buying a Mac Server (Maybe not server class hardware but obviously the server OS at least), and some commitment to learning how to do it all. You need to think about the effort it's going to require and decide if you really need all the options that badly.

Posted

We have OS X Server running on an XServe as of today, but this is the point at which I'm not making progress. My problem seems to revolve around the fact that when using Workgroup Manager in OS X Server, I cannot make any changes to preferences for Mac computers or any users - such as defining proxies etc. I cannot even make a new Computer List.

 

The error is usually with a code like 14140, eDSNoStdMappingAvailable.

Posted

Are you selecting the correct directory? With AD and OD, I must choose the OD and authenticate.

 

You will get Errors like that if you try to work with prefs when the AD is selected (as it doesn't have the correct schema)

Posted

You're trying to manipulate Active Directory to do this I presume?

 

You need to create an Open Directory Master on the Mac server, and use Open Directory to manage computer preferences.

 

For user preferences, you'll need to create groups in OD to contain the AD groups... which is a problem because (as you can see from some of the other threads here) OD to AD integration isn't all that it could be.

Posted
You're trying to manipulate Active Directory to do this I presume?

 

You need to create an Open Directory Master on the Mac server, and use Open Directory to manage computer preferences.

 

For user preferences, you'll need to create groups in OD to contain the AD groups... which is a problem because (as you can see from some of the other threads here) OD to AD integration isn't all that it could be.

 

Some issues can be reduced by increasing the max search results returned by AD, its set as 1000 by default. I think I boosted mine to 1500 - that way all users are returned correctly and no longer truncated.

Posted

I've now re-rolled the Mac server as Open Directory Master but kept the Kerberos Realm the same as my windows domain.

 

Can someone point me in the right direction for allowing users from the Windows AD to log in to a Mac based.

Posted

I my place we are using a mac server. We connect the OSX station to LDAP to mac osx server and active directory aswell. You can only really do preference changes to computers not accounts or groups.

 

Ross

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...