Jump to content

Mac Server and Windows Active Directory


Recommended Posts

Posted

Hi everyone

 

i have recently started using macs and i have just added my mac server to my windows active directory so that we can use single sign on but what i was wanting to know it keeps trying to pull the Documents folder down but because it is called My Documents it doesnt work is it possible to even seperate the accounts so that when they log onto mac it pulls the documents folder from the mac server instead of the windows server?

Posted
does anyone know why the mac clients would not be pulling down the policys from the mac server they log in through AD with no problems but dont seem to pull down any policy changes which i do on the mac server?
Posted
in WGM it is looking at the local side on the mac so i changed this to look through AD and then added a mac suite and the test Imac into that suite but again when i go back into local it doesnt appear. this is only available if using WGM i am searching through AD
Posted

To edit machine settings, you need to be working in the XServe's Open Directory - AD doesn't support MCX (Managed Client for OS X - the records used to control Mac clients).

 

In your XServe's directory (it should be the local one), make a machine group. You should then be able to add your AD computers as members of this computer group (assuming your XServe is bound properly to your AD, and your AD is properly set in your XServe's search path - check with "Directory Utility.app" in /System/Library/CoreServices).

 

Once your AD records for your Macs are members of the group you made, you can set the policies you want via the machine group with WGM.

 

[ N.B. Your iMac's need to be bound to both your AD and your XServe's OpenDirectory for this to work. ]

Posted

its very strange can anyone help with this, i have got the Mac server linked with active directory on my windows side and the Mac clients are allowing legacy users to log in using single sign on which is great but now the Mac server is really doing nothing because none of the changes i make for the Mac Clients are working. I have been using Work group Manager but it doesnt see any computers unless i select active directory and then when i do select this i cant create groups or make changes to individual computer policies for MAC.

 

I am not worried about the legacy equipment everuthing is working fine they are pulling policies and gpo through the windows server but all i wanted to do was allow any user to sign onto the mac clients but have the mac server sort everything else out for Mac's is this possible?

Posted

You need to create the groups using open directory in workgroup manager. The group will appear in the left hand column and in the right hand side of the application you will have two-three tabs: basic, members and if enabled, inspector. Click members then click on the plus sign and a tray will slide out. At the very top of that tray you'll see Directory: /LDAPv3/127.0.0.1 click the downward facing chevron next to the globe and select your active directory domain and add your computers that way.

 

Ideally you should use a magic triangle configuration which means the Mac server is bound to AD, but is also an open directory master. Then bound the clients to both AD and OD that way they login with an AD account and get network documents, but they also get managed policies from your XServe. Computer accounts will be created in both AD and OD for this to work.

Posted
unfortuneatley that doesnt seem to have worked it looks like the imac is actually getting its policies from the windows side and isnt regestering anything on the mac side is there some step that ive maybe gone wrong with the server doesnt seem to see any connections on the server at the moment.
Posted
You will have to bind the client to the open directory on the mac server for machine policies to be pushed down. Your clients are probably currently bound to only AD thus they have no reason to grab the policies being pushed down from the server. The only way for your current setup to work is to edit the individual policies on locally each of your mac clients. Binding the clients to your mac server is much easier though. Just make sure your Mac server is setup correctly and that your DNS servers are in good condition.
  • Thanks 1
Posted
thanks stevehp the clients are bound to AD it was one of the steps i went through so i just unbind them from AD and then bind them to the mac server instead?
Posted
If i unbind the clients does this stop users from authenticating to them or does the mac server still allow this to happen so that i am still able to use single sign on?
Posted
No, the mac clients would be bound to both AD and OD. AD would still provide your authenication services, but now with the client bound to OD it can receive machine policies.
Posted

hi stevehp

 

i have tried binding the mac clients to the mac server this morning but it keeps coming up with unexpected error has occured this action has been cancelled, not sure what is wrong here it is asking for the diradmin account to link the imac to the server which is diradmin and then the password this then brings up the error and then i try again at another stage and it asks me for the local admin account username and password enter in the info and the same error pops up. Have you ever seen this before?

Posted

Got it sorted there just open ldapv3 and removed the server settings and readded the server and it worked first time added the machine to the Mac OD and was able to add this to the suite so now its just a case of setting the preferences to the mac.

 

thank you for all your help

Posted

I was wondering is it possible now that the clients can use single sign on can i then seperate it further by saying that when a user logs onto a standard windows xp it picks the documents up from windows file server but when a user then logs onto the Imac clients can they pick the documents from mac but also have a link to the windows documents at all?

 

this would then help with seperating out the documents folders so that i can use mac to backup all the mac work and the windows backup to backup windows work. what i am really wanting is that although the users can logon to any computer in school there documents for the mac side comes from the mac server and the documents from the windows side comes from windows server.

 

Is this possible at all?

Posted

It's possible, but it's a pain in the backside.

 

They're called augmented records and it will allow you to have one user from one directory (AD in this case) have two home folders.

 

I attempted augmented records, but for the amount of users we have it wasn't time efficient as it requires a lot of hand editing the users inspector records. I'm sure some scripting genius could have automated a good deal of it but I'm no genius in that regard. You're better off with the magic triangle configuration where your established active directory domain serves both single sign on authentication and home folders.

  • Thanks 1
Posted (edited)

Hi

 

"Is this possible at all?"

 

Yes and it's easier than you might think. Although it depends on how you have your AD Users Profile Settings configured? There's actually no real need for Augmented Records (which is just another way of doing AD-OD Integration or, if you like, Magic Triangle) either. If you've specified their Home Area location in the Profile Path then you simply add another Home Area location in the UNC Path and assign a suitable Drive Letter. This can be anywhere you like. Even a Mac Server. Assuming your Mac Server has the capacity and you've defined a suitable share point appropriately?

 

All you need do thereafter is assign appropriate redirects using the Global Policies Management Console for the home area defined in the Profile Path and you've achieved dual homes. One for Users when they log into a PC and one for when they log into a Mac. Again depending on how you've structured and configured your AD this could be hard or easy work?

 

From there your only possible problems are - albeit minor ones - finding some way to synchronize the data. Or at the least give access to Users Data depending on which platform they log into. Assuming this is something you want to provide? Your other potential issue will be backup. Clearly all this data - and once Macs are involved there will be lots of it, more than you think - will need backing up somewhere? Presumably? Although even this can be failry easily accommodated with a little bit of thought and with potentially no need for extra expense. Your only other problem after that is acquiring enough knowledge (a training course would be ideal/useful) in supporting a platform which is unfamiliar to you.

 

HTH?

 

Antonio Rocco (ACSA)

Edited by AntonioRocco
  • Thanks 1
Posted
hi guys from what i could see today when i have changed the folders on the main server this is now allowing me to login to the windows machines and pick up my documents and also now if i log into the mac its showing my documents from the windows side although if i save to the mac it is saving this locally. Is it possible for a share to be made on the mac server to allow instead of saving locally that it saves to the Mac server so that if the users need access to windows documents thats still possible but all mac saves go to the mac server.
Posted
at the moment now when a user logs into the imac clients at the bottom of the dock it shows documents which is from the windows side so this is great but when i open a new document or file and hit save it seems to save locally i would like to change this instead of saving locally to the machine it saves to the Mac server share for there documents.
Posted

Thanks guys for all your help all working great now at the moment what i have done is gone with the mobile home documents and set on the file server to locate to the apple mac server for there documents then set a share to the windows file server on the macs so that users can get access to windows files. It also means mac users on the windows side and get access to those files as well if needed. The normal windows users can log into the mac's now but save locally which isnt backed up whcih i dont mind because they would only be doing general searching really and I have left folder redirection on the windows side so that when the users log in they get there windows documents.

 

Thank you very much guys for all your help really has been a great help to get me this far

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...