Jump to content

AntonioRocco

Members
  • Posts

    354
  • Joined

  • Last visited

Reputation

1,028 Excellent

4 Followers

About AntonioRocco

Personal Information

  • Biography
    Apple Specialist in Active Directory Integration • Advanced Macintosh Deployment • Advanced Macintosh Management • iOS Deployment and Management • Advanced OS X Server & Deployment Training • Bespoke Mail, Contacts & Scheduling Services for Enterprise • Small to Medium Networks and all things Apple. Primarily for the Midlands and Yorkshire areas but will consider anywhere else.
  • Occupation
    Apple Consultant & Systems Engineer
  • Location
    South Yorkshire

Employer (optional)

  • Company Represented
    ARC Apple Consultants & Systems Engineers
  1. "No, I mean 2012" Can't see how? I've had a mid-2012 MBP from new and I can only run macOS Catalina as later OS are not supported (or even installable) on that hardware. Not that it matters but I would look at what you've got closely and think again. I think the solution you ended up using is probably the best for your situation. If you don't have a large-ish Mac estate I wouldn't bother with ARD as it does it have its quirks which can make it difficult to use. Good luck.
  2. "MacOS Sonoma on a 2012 MBP . . . " Perhaps you meant 2021 MBP? I would go Brimstone's suggestion which is ideal for remotely controlling and managing to some degree Macs in a local network. Does not respond too well if you've a segmented network although it's easy to get round the limitation. Obviously you're better doing this Mac to Mac. Other alternatives are CoRD which you could look at. TBH ARD is probably the way to go.
  3. It may be an issue with Plickers as what I suggested does not happen in my experience. However I don't use Plickers. Try the app's developers. Perhaps they can help?
  4. As part of the lesson could the teacher (as part of his/her duties) advise the students to double-tap the home button and swipe safari closed before the end of the tutorial or lesson. Should achieve the result you want?
  5. Only just seen this post. Too late now but I saw something very similar years ago. Ended up involving legacy versions of the server OS being upgraded (rather than clean installs) over successive years. 'Ghost' users/groups with legacy user names (including the system user) had been applied with associated permissions in the past and seemed to be 'glued' to shares/folders. Ordinarily these did not seem to cause any major problems with PC users but once Macs were introduced then oddities like the one you describe began to appear. Once these 'ghost' users/groups with their associated permissions were removed the problems faded away. Not much help now I know as you seem to have figured this out anyway and if it is as you surmise then well done! Antonio Rocco (ACSA)
  6. If your Macs are joined/bound to AD and all your users are in AD then Open Directory has nothing to do with how strong their pass-phrases are going to be or anything else. Profile Manager is used to apply policies to control and manage the user login experience. Have a look at Profile Manager because there may be a policy that's being applied to device groups that might be interfering with it somewhere? Open Directory only comes into play in terms of password policies if users exist in OD and not in AD. Somehow I can't imagine this being the case at your institution? If I've understood your situation correctly, when there is a password policy change, users logging onto Macs (or PCs) should get a prompt to change their passwords. This would be expected behaviour, everyone moves on and continues as normal. Clearly you're not seeing this on the Macs in which case it might have something to do with users having saved their (now expired) previous passwords using Keychain Manager. Advising users to reset their Keychain (when they see the prompt on a password policy change) should force Keychain Manager to forget the previous password and accept the new one. Hopefully they should not get the prompt again. Slight caveat with this is that Keychain Manager can be a bit flakey at times and will (usually) only allow you to do this once. This used to be the case with macOSes prior to Catalina. Not sure what happens with the latest macOS (Big Sur)? In theory Keychain Manager is a good idea but in an AD environment it can hamper things in situations like yours. Nothing to do with the complexity of the password policy but more to do with expired passwords. Keychain Manager works by supplying the previously saved password to allow the change to the new one. But if that password has expired how can it effectively do that? If it turns out to be Keychain Manager then the NOMAD app might help you through the problem?
  7. I remember seeing something similar about 10 years ago. Turned out to be the management software the school was using had somehow imposed a restriction on booting from USB attached drives. It's a long shot but have a look at what you're using to manage the Macs. Perhaps the issue is there? On another note I would always do a nuke and pave upgrade to a newer OS rather than an in place upgrade of an older OS. It's a bit more work but saves you potential headaches in the longer run.
  8. Perhaps your issue is to do with Apple's Security Boot feature introduced since the T1 & T2 chipsets were made available? https://support.apple.com/en-us/HT208198 I think the 3rd option on the Secure Boot part of the menu might help? Good luck!
  9. Not familiar with Mac Admin. Maybe you mean WorkGroup Manager? If you do then yes I agree. Post 10.7 Apple replaced it with Profile Manager. I still have an active 10.6 server working perfectly well which I use myself. I also know of two more other sites I support also working perfectly well. After 2009 it became clear Apple were moving out of Enterprise in the traditional sense and developing their own "Enterprise" methodology. Hence the resulting BYOD, MDM, ASM and so on. It's the logical way to go when you consider everything involved in modern society with mobile devices being just as or more important than traditional computers. Once again good luck and if you think you may need a hand then please don't hesitate to contact me. Antonio Rocco ACSA
  10. Apologies for all the questions and I can see you've been dreading where they were leading too. I can tell you now (in my experience) lists of users with pictures have always worked reliably going back to 10.3 (Panther) all the way up to 10.8 (Mountain Lion) at numerous sites. A single server was all I was using same as you. DNS definitely not based around .local. The thing is .local fools you into thinking it works but it doesn't really. At best it throw up oddities like the ones you see and at worst its downright unreliable. It can also seriously fubar the OD database. If you're not planning to rebuild/renew your OD once a year then those inconsistencies caused by .local only get worse. Obviously it's your choice but if AD is not involved I really can't see the sense in continuing with it. The sooner you get it changed to something else the better you'll be and the more reliable things will get. Good luck. Antonio Rocco ACSA
  11. Is this a standard OD environment with an OD Master and Replica and possibly a 3rd Mac server used for DNS and DHCP? If so what is your domain based around? Have you used .local or something else? Antonio Rocco ACSC
  12. Is the OD environment separated from your AD network with a mac server (or servers) providing DNS & DHCP services to your mac clients? Antonio Rocco ACSC
  13. Which VNC viewer are you using? If you're using something like RealVNC or TightVNC from a PC then you must enable the "VNC viewers may control screen with password" setting in the Computer Settings section when enabling Remote Management. Don't use the same local admin user's password. You may also have to tweak colour and resolution settings on your VNC viewer when attempting to make the connection. Even then YMMV. I think your other problem is probably network related? Most enterprise/school networks don't routinely route VNC traffic from wired subnets to wireless ones. That would explain why you can't ping etc. I would investigate this first before looking at a potential hardware issue. Antonio Rocco (ASCA)
  14. Just a suggestion but have any of the users experiencing the problem signed into iCloud using a browser by any chance? Due to the randomness of the problem I'm thinking that could be the reason? If you've enabled logging on your proxy/web filter server then you could inspect them and see if they correspond when an end user reports the problem.
  15. Just to clarify a few points regarding Apple Remote Desktop. Specifically the Admin part of ARD which is a separate application. ARD (the client part) is built into and is part of the OS and has been from at least 10.2 (Jaguar) onwards. The option that shows a client Mac if they're being observed can be turned on or off. So they need not be aware they're being observed. It's also a two-way thing as it allows the client Mac to contact (send a message) the administrator (or teacher) using it. You don't have to use ARD Admin on a (Mac) server. I would never recommend it as it's best used on a normal Mac. Usually the one designated to be the IT administrator's Mac, or in certain cases, the teacher's Mac. Amongst other things it's a very powerful data gathering tool allowing you to audit all your Mac estate. Things like serial numbers, hardware specs, processes using the most memory and so-on. Hope that helps? Antonio Rocco (ACSA)
×
×
  • Create New...