Jump to content

AntonioRocco

Members
  • Posts

    354
  • Joined

  • Last visited

Everything posted by AntonioRocco

  1. "No, I mean 2012" Can't see how? I've had a mid-2012 MBP from new and I can only run macOS Catalina as later OS are not supported (or even installable) on that hardware. Not that it matters but I would look at what you've got closely and think again. I think the solution you ended up using is probably the best for your situation. If you don't have a large-ish Mac estate I wouldn't bother with ARD as it does it have its quirks which can make it difficult to use. Good luck.
  2. "MacOS Sonoma on a 2012 MBP . . . " Perhaps you meant 2021 MBP? I would go Brimstone's suggestion which is ideal for remotely controlling and managing to some degree Macs in a local network. Does not respond too well if you've a segmented network although it's easy to get round the limitation. Obviously you're better doing this Mac to Mac. Other alternatives are CoRD which you could look at. TBH ARD is probably the way to go.
  3. It may be an issue with Plickers as what I suggested does not happen in my experience. However I don't use Plickers. Try the app's developers. Perhaps they can help?
  4. As part of the lesson could the teacher (as part of his/her duties) advise the students to double-tap the home button and swipe safari closed before the end of the tutorial or lesson. Should achieve the result you want?
  5. Only just seen this post. Too late now but I saw something very similar years ago. Ended up involving legacy versions of the server OS being upgraded (rather than clean installs) over successive years. 'Ghost' users/groups with legacy user names (including the system user) had been applied with associated permissions in the past and seemed to be 'glued' to shares/folders. Ordinarily these did not seem to cause any major problems with PC users but once Macs were introduced then oddities like the one you describe began to appear. Once these 'ghost' users/groups with their associated permissions were removed the problems faded away. Not much help now I know as you seem to have figured this out anyway and if it is as you surmise then well done! Antonio Rocco (ACSA)
  6. If your Macs are joined/bound to AD and all your users are in AD then Open Directory has nothing to do with how strong their pass-phrases are going to be or anything else. Profile Manager is used to apply policies to control and manage the user login experience. Have a look at Profile Manager because there may be a policy that's being applied to device groups that might be interfering with it somewhere? Open Directory only comes into play in terms of password policies if users exist in OD and not in AD. Somehow I can't imagine this being the case at your institution? If I've understood your situation correctly, when there is a password policy change, users logging onto Macs (or PCs) should get a prompt to change their passwords. This would be expected behaviour, everyone moves on and continues as normal. Clearly you're not seeing this on the Macs in which case it might have something to do with users having saved their (now expired) previous passwords using Keychain Manager. Advising users to reset their Keychain (when they see the prompt on a password policy change) should force Keychain Manager to forget the previous password and accept the new one. Hopefully they should not get the prompt again. Slight caveat with this is that Keychain Manager can be a bit flakey at times and will (usually) only allow you to do this once. This used to be the case with macOSes prior to Catalina. Not sure what happens with the latest macOS (Big Sur)? In theory Keychain Manager is a good idea but in an AD environment it can hamper things in situations like yours. Nothing to do with the complexity of the password policy but more to do with expired passwords. Keychain Manager works by supplying the previously saved password to allow the change to the new one. But if that password has expired how can it effectively do that? If it turns out to be Keychain Manager then the NOMAD app might help you through the problem?
  7. I remember seeing something similar about 10 years ago. Turned out to be the management software the school was using had somehow imposed a restriction on booting from USB attached drives. It's a long shot but have a look at what you're using to manage the Macs. Perhaps the issue is there? On another note I would always do a nuke and pave upgrade to a newer OS rather than an in place upgrade of an older OS. It's a bit more work but saves you potential headaches in the longer run.
  8. Perhaps your issue is to do with Apple's Security Boot feature introduced since the T1 & T2 chipsets were made available? https://support.apple.com/en-us/HT208198 I think the 3rd option on the Secure Boot part of the menu might help? Good luck!
  9. Not familiar with Mac Admin. Maybe you mean WorkGroup Manager? If you do then yes I agree. Post 10.7 Apple replaced it with Profile Manager. I still have an active 10.6 server working perfectly well which I use myself. I also know of two more other sites I support also working perfectly well. After 2009 it became clear Apple were moving out of Enterprise in the traditional sense and developing their own "Enterprise" methodology. Hence the resulting BYOD, MDM, ASM and so on. It's the logical way to go when you consider everything involved in modern society with mobile devices being just as or more important than traditional computers. Once again good luck and if you think you may need a hand then please don't hesitate to contact me. Antonio Rocco ACSA
  10. Apologies for all the questions and I can see you've been dreading where they were leading too. I can tell you now (in my experience) lists of users with pictures have always worked reliably going back to 10.3 (Panther) all the way up to 10.8 (Mountain Lion) at numerous sites. A single server was all I was using same as you. DNS definitely not based around .local. The thing is .local fools you into thinking it works but it doesn't really. At best it throw up oddities like the ones you see and at worst its downright unreliable. It can also seriously fubar the OD database. If you're not planning to rebuild/renew your OD once a year then those inconsistencies caused by .local only get worse. Obviously it's your choice but if AD is not involved I really can't see the sense in continuing with it. The sooner you get it changed to something else the better you'll be and the more reliable things will get. Good luck. Antonio Rocco ACSA
  11. Is this a standard OD environment with an OD Master and Replica and possibly a 3rd Mac server used for DNS and DHCP? If so what is your domain based around? Have you used .local or something else? Antonio Rocco ACSC
  12. Is the OD environment separated from your AD network with a mac server (or servers) providing DNS & DHCP services to your mac clients? Antonio Rocco ACSC
  13. Which VNC viewer are you using? If you're using something like RealVNC or TightVNC from a PC then you must enable the "VNC viewers may control screen with password" setting in the Computer Settings section when enabling Remote Management. Don't use the same local admin user's password. You may also have to tweak colour and resolution settings on your VNC viewer when attempting to make the connection. Even then YMMV. I think your other problem is probably network related? Most enterprise/school networks don't routinely route VNC traffic from wired subnets to wireless ones. That would explain why you can't ping etc. I would investigate this first before looking at a potential hardware issue. Antonio Rocco (ASCA)
  14. Just a suggestion but have any of the users experiencing the problem signed into iCloud using a browser by any chance? Due to the randomness of the problem I'm thinking that could be the reason? If you've enabled logging on your proxy/web filter server then you could inspect them and see if they correspond when an end user reports the problem.
  15. Just to clarify a few points regarding Apple Remote Desktop. Specifically the Admin part of ARD which is a separate application. ARD (the client part) is built into and is part of the OS and has been from at least 10.2 (Jaguar) onwards. The option that shows a client Mac if they're being observed can be turned on or off. So they need not be aware they're being observed. It's also a two-way thing as it allows the client Mac to contact (send a message) the administrator (or teacher) using it. You don't have to use ARD Admin on a (Mac) server. I would never recommend it as it's best used on a normal Mac. Usually the one designated to be the IT administrator's Mac, or in certain cases, the teacher's Mac. Amongst other things it's a very powerful data gathering tool allowing you to audit all your Mac estate. Things like serial numbers, hardware specs, processes using the most memory and so-on. Hope that helps? Antonio Rocco (ACSA)
  16. Does not matter whether they're new or not, it's all about the home folder which can get quite large quickly. Simply logging in will create almost 200MB of data and that's before a program is launched. It won't take long to accumulate 1GB of data and more especially with the courses schools tend to use Macs for. If you're applying quotas that could be an area you could investigate further? Looking ahead and only if time and inclination allows you could try creating a smaller stand-alone testing network where .local is not used and see if the problem disappears. Antonio Rocco (ACSA)
  17. ". . . newer accounts have less problems . . ." Sounds like it could be all the crud and cruft (junk in the attic) that builds up over time with any computer? I would focus on existing users' Home/Library folders. Specifically cache files (bin them), ByHost files (in fact bin the whole ByHost folder) and files in the Preferences folder. Depending on how many users you have it's a lot of work and if it turns out to be corrupted files in the Home/Library folder then think about developing a strategy that bypasses the problem. Ideally and if time allows in the summer recess I would refresh/rebuild all Macs as a matter of course as well as treating existing users as if they were new users. There should be nothing they could want or need in their home folder anyway as their data should be elsewhere. A lot depends on what courses the students are using the Macs for. If for Video they should be working locally anyway and saving their data to a network share or locally attached drive. Music and Graphic Design not so much although that depends on what software they're using and the complexity and size of projects they're working on. It's been obvious that with each successive macOS upgrade - the last 2 (Mojave & Catalina) at least - Apple are making it more difficult to work with home folders stored on a network share. Only my opinion but I think their strategy is focused on BYOD (iPhone, iPad or Mac) regardless of whether its Business or Education. Good luck!
  18. That's the problem with using .local. You get random oddness that, sometimes, make no sense. Are logins slower than usual for the students affected when compared to those that are OK or are they the same? Look at what permissions are set for invisible files such as the ".TemporaryItems" folder that macOS creates whenever a folder is accessed. It's possible invisible folders are owned by admin users and disallowed for everyone else or (possibly) only those affected? Are student homes all on one share or spread across multiple shares on separate servers/network drives? Antonio Rocco (ACSA)
  19. This could be down to a permissions issues and not necessarily anything to do with accounts themselves? If you're nesting student homes within other folders (usual practice for Windows Networks) then you may see this behaviour if you don't allow at least list and/or read permissions downstream to the folder containing the student homes. Permissions may have been iterated for some but not all? Worth investigating perhaps? I've also seen this in networks where .local is used for domain suffix. This can cause timeouts when DNS lookups performed by the Macs conflict with Bonjour. I've also seen the problem with RJ45 splitters being used to share one network port with two workstations especially on 100 BaseT networks. Does nothing happen or do you get an error when you click on the question mark or does the network home icon appear? Antonio Rocco (ACSA)
  20. AntonioRocco

    Renaming Mac

    Not sure if I have anything that helps but IIRC naming convention is limited to 15 characters. So whatever naming convention you've chosen try to keep within that limit otherwise it may become confusing. TBH I'm struggling to see how it would work if different users are logging onto workstations? If it was one person per workstation, fine, as you could make the script part of the deployment process. But on the fly as different users log in during the day, awkward, especially in terms of DNS records going stale very quickly which could give rise to failed logins as well as other network related issues. Looks like you may be on your own with this one? Good luck if you manage it. Antonio Rocco (ACSA)
  21. There's no way of enabling ARD remotely without either (a) enabling the service from the beginning when building your mac 'golden image' prior to deploying it. Some of the recommended Mac deployment methods are: DeployStudio, NetBoot, AutoDMG etc. Hopefully you may be familiar with at least one of these? If you're using SCCM and you've enabled the Mac Client part of SCCM then you should be able to use that instead using the details outlined below. Quick question: did you or have you enabled SSH on all your Macs by any chance? If NO then again you'd have to enable it from the beginning as their's no way of enabling that remotely either. AFAIK and unless someone else offers something that works for your situation then your only alternative is to go to each one in turn, log in as the local admin and enable the service from the Sharing Preferences Pane. Tip: Hold down the option/alt key when you click the first check box from the options button when you enable the service as this will tick all the check boxes at the same time. If YES then launch Terminal on the Mac you use for administering all your other macs and make sure you're in the same subnet as those Macs first. From the Shell Menu select New Remote Connection. In the Service section for SSH you should see the Macs Bonjour names in the Server section. Select one first and in the User field at the bottom of the window key in the local admin user's name (lower case letters). Click Connect and a new Terminal window will open warning you about RSA key fingerprints. Key in the word yes followed by the carriage return and you'll then be prompted for that users password which you won't see being typed. If successfully connected you should see: Last login: the date name-of-Mac-you've-connected-to:~localusername To enable ARD use this command: /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -access -on -users admin -privs -all -restart -agent Followed by the carriage return. The admin part of the command above should be changed to what you've configured as the localadmin user name for all your Macs. If you'd used local admin then change the above to localadmin. Don't create another local admin user as Apple 'Best Practices" recommends you do it this way. Besides you'd have to go round each Mac in turn to create yet another user. You can copy/paste the above into the terminal window. Do this for each Mac in turn. If you've used DeployStudio before to deploy your golden image to all your Macs and you're familiar with it, you could define a one-time workflow with a single script that enables both services. SSH is very useful when troubleshooting and a great means of communicating with your Macs other than ARD. It's also a great way of restarting the ARDAgent when it plays up - which it will - occasionally. Defining a script that will do this will look like this: #!/bin/sh #Enabling SSH & Remote Management systemsetup -setremotelogin yes /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -access -on -users admin -privs -all -restart -agent exit 0 Again you can copy/paste the above into one of the sample scripts. Make a copy of the sample script first before overwriting it and name it something meaningful. DSCL stands for Directory Services Command Line and is a very powerful tool in not only interrogating homogenous directory services such as Open Directory and Active Directory but also in creating, editing and deleting users. Either locally or on a directory server such as Apple's Open Directory. So be careful using it! You can't edit, create or delete users in Active Directory using DSCL. The Catch22 with DSCL is you need to enable SSH or ARD first before you can use it remotely on your Macs. Does this help? Antonio Rocco (ACN)
  22. I may be in danger of teaching granny to suck eggs but Citrix Receiver (now Workspace) may help? https://www.citrix.com/en-gb/downloads/workspace-app/mac/workspace-app-for-mac-latest.html
  23. Don't mean to rain on your parade but moving to Jamfpro won't iron out any existing network issues you see with your macs. Not only is gigabit to desktop a must but DNS is crucial especially if you're using .local for the domain TLD. If your Windows domain is built around this, and depending on the namespace you've used, your Macs will be unreliable. Besides any 'Mac Management' software will require DNS to be as rock solid as it can be for your Mac estate irrespective of which one you decide to use. Having said that, your issues could be down to the applications used. Most applications of my experience are not 'designed' to work over a network. I don't know of any Music or Graphic Design applications that do. The fact that some do (mainly) is a happy bonus and probably due to using a gigabit network and internal DNS services not based around .local. For your sake I hope I'm wrong as JamfPro is a hefty investment to make if it proves not to improve things for you Macs.
  24. I've installed 1TB IDE HDDs in the Mirrored Doors G4s and they've worked fine. I'm also looking at a similar G4 to yours that has a 500GB IDE drive installed and that too works fine. You can get a SATA connection kit that works well in the PowerMac G4 range. Hope this helps?
  25. Not had chance to catch up with this myself yet but the following may make things clearer? https://simplemdm.com/2017/11/01/user-approved-mdm-enrollment/ Antonio Rocco (ACSA)
×
×
  • Create New...