-
Posts
354 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by AntonioRocco
-
Finder browsing the SYSVOL and NETLOGON folder
AntonioRocco replied to networkmanager's topic in Mac
Hi Disable "NetBIOS over TCP/IP" in the DHCP Service's Advanced Section. When was the last time you had to support NetBIOS aware client workstations? Customizing the Sidebar's plist is one way of doing this although by itself it still won't stop users from re-enabling the view by accessing the Finder Preferences. The trick is to deny them access to this Setting as well. However this may cause more problems than it solves. Why is it such a problem? Surely if authentication and authorisation along with permissions has been correctly set on server and client workstations what difference would it make? Should you not be storing SYSVOL on another volume for performance reasons anyway? One that is not being shared. Hard drives are not expensive. Antonio Rocco (ACSA) -
Hi Ranj AFAIK defining a script as Full Backup means it will be Incremental. This is how it used to be in previous versions of Retrospect and from what I've seen so far it does not seem to have changed that much. For what you want to do and to keep it simple you could do it with two scripts? One for Monday to Thursday and one for Friday. Monday's tape will be the Full Backup and Tuesday through till Thursday will store the Incremental changes based on Monday's catalog. The first time Friday is run will be the full backup and the following Friday will just be the Incremental changes based on the previous Friday's Catalog. Over time incremental backups will invariably span multiple tapes unless you plan to rotate the tapes on a monthly or quarterly cycle (for example) before they start requiring a second tape. Does this help? Antonio Rocco (ACSA)
- 1 reply
-
- 1
-
-
Hi AFAIK there is no free application for to recover deleted data. The major ones most people on the platform use are: Computer Data Recovery, Mac Data Recovery Software, Mac Data Rescue, Digital Data Recovery Disk for Mac - Data Rescue 3 Mac Data Recovery Software, Data Recovery Mac ? Mac File Recovery Mac Data Recovery Software - Recover data from Apple Mac Drive - Apple Mac Recovery - Data Recovery Mac Another one is FileSalvage which a link has already been provided. I have known this to be somewhat successful. You have to be quick though. There may be some others which you could google for yourself? Although not an application designed to recover deleted data DiskWarrior makes a good job (sometimes) of recovering a drive (and its data) that is not accessible by the usual means. All of these applications have a price tag attached. I know it's not what you want to hear but the 'best' way to recover data is to have a sound and effective backup strategy in place. Which you more than likely already have. Not 100% foolproof I know but it's probably the best chance you have? As ever the longer you leave the attempt at recovering deleted data the less chance there is of recovering anything useful. Especially if you're still using the affected mac. The platform at its heart is UNIX based. Once a file is deleted the blocks are made ready to receive new data which makes it doubly difficult. Even booting the affected mac will alter its state at a block/directory level. This makes it harder still. AFAIK, on a mac, once it's gone it's pretty much gone for good. Sorry. Antonio Rocco (ACSA)
-
Hi Sidewinder You're welcome. Judging from what you're saying in addition to a definitive screen grab it looks like there is a problem with it. That error message I've not seen before . . . yet. A call to AppleCare or the Reseller (if used) would be the next thing to do. Judging by the MacPro Apple RAID Card the Battery itself is not that difficult to replace. It's about the size of an After Eight Mint and about as thin. Having never replaced one in an XServe it's not certain if it's the same? You can run the Server whilst it's like this but don't leave it long. If there's a drive failure there is a potential for data loss on top of increasingly poor performance. Antonio Rocco (ACSA)
-
Hi Strange as it displays OK for me? Are you accessing the site via a Proxy by any chance? Is this Proxy tied in with an AD Policy in some way? Perhaps an AD applied Filter which works fine with IE and not Firefox? What happens if you add a client workstation to your whitelist and try again? Have you tried downloading Opera or Mozilla or even Netscape for OSX to see if the problem persists? There may also be other alternate browsers which you could Google for yourself? Microsoft dropped support for IE on the mac platform about 3-4 years ago. The last version was 5.2.3 IIRC? I doubt if you'll have much joy with it if the OS is Snow Leopard 10.6 as support via Rosetta for older applications is limited. It's possible it may work if the OS is Leopard 10.5? Even if it did work It may have a problem displaying some sites? Antonio Rocco (ACSA)
-
Hi The battery on the Apple RAID Card is not charged the first time you take the Xserve (or MacPro) out of the Box and power it on. It takes roughly 72 hours for it to fully charge. Whilst this is happening the XServe should not be powered down. If it is the battery will begin to recharge itself from the beginning again and again. Once the battery is fully charged you should enable the Write Caches option (actually you should do this as soon as possible) as this will help performance. There may be a slight performance loss whilst the battery is being charged. Every 3-4 months the battery will discharge itself as part of its reconditioning cycle. This is normal. The RAID Utility application will warn you of this. It will take 72 hours before its fully charged again. Again it's important to not power down the XServe whilst this is happening. This information might be slightly different now as Apple have improved battery handling and logging in the newer models. This statement: "Only had out new xserve a few months, but already, every time its booted up, I get a prompt" Why are you having to boot it up every time? Is there a problem that only a reboot seems to cure? Most servers are generally on 24/7. Apple have many support documents available regarding the RAID Card: Mac Pro RAID Card and Xserve RAID Card: Frequently Asked Questions (FAQ) If you have not already done so run all the available updates for the XServe as well as OSX Server. Pay particular attention to any firmware updates that may be available. As with any Server update make sure you have a fully bootable backup clone of the Server before committing to a Server update. There are no rollbacks on the Mac platform. "Would Apple send out under warranty or charged as a comsumable?" AFAIK the Apple RAID Card Battery is not dealt with the same way an Apple laptop battery is. Assuming there is a fault with the Battery then it would be covered under the warranty. What's not clear is if there is actually a problem? I've done quite a few of these since they first came out and I've only seen one that was faulty, sort of. "Do have to buy one? Do they sell them?" If it's covered under the warranty, No. Apple (or any Apple Service/Repair Specialist) will sell you anything they make. Antonio Rocco (ACSA)
-
Hi "Has anyone else encountered this?" Yes and No. Assuming your AD structure is fairly flat then you could query it from a bound mac workstation using the command line utility dscl. See if the groups can be correctly accessed. For usage launch Terminal and issue man dscl. It's fairly obvious thereafter. Do these groups appear in WorkGroup Manager? Can you see individual user membership of those groups within WorkGroup Manager? To view Active Directory LDAP records using WorkGroup Manager enable the Inspector Option. Launch WorkGroup Manager, click on the WorkGroup Manager Menu, select Preferences, enable the option to "show all records tab and inspector". You can safely dismiss the warning dialog box that follows. Don't worry about deleting or modifying the AD Schema using this method. Remember you only have read only access to a bound LDAP schema. What you should see now is the addition of an extra icon (looks a bit like a bullseye) as well as an extra tab labelled Inspector. Select this and you should be able to authenticate to the /Active Directory/All Domains node by providing an AD admin account that has authority for the AD Domain. Select a Group you're interested in and inspect its Group membership. Does it tally with what you see in AD? What about adding the General Domain Users Group OU instead? Would not this OU be populated with all users automatically anyway? Antonio Rocco (ACSA)
-
Hi Boon72 To clarify: If your server is in an AD environment and is not a Mail Server and/or 'full' OD Master - ie: KDC and providing user homes - there's no reason why you can't use Time Machine. I would always build into any backup 'strategy' test restores. You don't really have a backup 'strategy' otherwise do you? If you're running a separate OD environment use Time Machine at your own risk. In either case archiving the LDAP database (which can be scripted and scheduled) and/or exporting Users/Groups/Lists etc is always a good idea in addition to a live clone of the Server either using CCC or SuperDuper or a non-live clone using Disk Utility. Assuming your hardware supports it I would supplement all of the above with a UPS (separate ones for an XServe) and mirrored drives or better still a Hardware RAID. Antonio Rocco (ACSA)
-
Hi Time Machine is not recommended as an option by Apple themselves for Servers configured as Advanced. Strictly speaking this only really applies if the Server is a fully fledged OD Master with all that that entails and/or a Mail Service. Backing up any 'live' database - LDAP and/or Mail - is going to be risky without first stopping the services. Not so much of a problem with Mail but with LDAP it could become a problem? Sometimes Kerberos stops and never starts again. Although there are ways around this that works sometimes. It's not so much the backup that's the problem. It's the restore - as already mentioned. What's the point of backing up if all you ever recover when disaster strikes is useless? In an Active Directory environment I doubt this would be the case? Most mac servers in such environments probably don't have more than 2-4 services running in any case? What little there is of the LDAP database would only contain OD Groups nesting AD Users and/or Groups. Any Policies would be associated with those Groups as well as any OD Computer Groups. There are no passwords to worry about either and neither is there anything 'live'. MCX or mac-style Policies once applied are 'static' settings and only change when a policy is updated or added. To be honest the only thing worth 'backing' up, apart from any pertinent data - which you should be backing up in any case - would be those OD Groups/Computer Lists. You don't need to do anything special in that case as you could simply export them from WorkGroup Manager. Archiving the LDAP Database would achieve the same thing. If the worse happens and the server dies for any reason it's sometimes quicker to reformat/reinstall and re-import or restore after successful 'bind' to AD and promotion to OD. Both processes are not exactly time consuming are they? Having said all that Apple's 'Best Practices' suggests using DU when booting from the Installer Disk and saving the server's 'state' as a .dmg to a share or externally connected drive. For a vanilla server you're probably talking about 8-12GB? This should take roughly 30-40 minutes. There's nothing wrong with using CCC either. With CCC you can even scheduled cloned backups and what's more it will do it (successfully) whilst the server's 'live'. Another solution you could look at is SuperDuper which does have a price tag. Hope this helps? Antonio Rocco (ACSA)
-
Hi You have to add the domain name in the Search Domains field in the Network Preferences Pane. You could of course use your DHCP Service to do this for you. Can you resolve the DC on both pointers from a mac client? Try not to use ping. Use something actually useful instead, like nslookup, dig or host. Whilst you're at it make sure your DC can resolve itself on both pointers also? Antonio Rocco (ACSA)
-
Hi "Not got that utility on these macs" You have. Apple moved it in 10.6. You can now find it in /System/Library/CoreServices. You should use the Advanced section available in the Active Directory Plug-in to configure mac clients correctly. Your problem is more to do with Windows Servers (generally) are not very good (in my view) at keeping time. It might be better if you 'pointed' your DC to an upstream stratum NTP Server and then 'point' all your clients to that instead. There are known problems with 10.5 and 10.6 clients maintaining a persistent link to Active Directory. What is interesting is this not true for all locations. Clearly this seems to indicate a difference/problem between your environment and environments where the problem does not exist? If you have access to another AD environment where the problem does not exist and compare it to yours then maybe you can begin to cure the problem? Successful Integration is not only about Time Synchronization. Although it is important. More important still is a correctly configured and working DNS Service not based around .local. Apple have made it possible since 10.5.4 to allow client workstations to work with AD domains using .local however that's not a guarantee that it will work without problems. If your environment's domain is based around .local as the .TLD then you may have more success if you disable mDNS/Bonjour on your mac clients instead? You could test this on one client and if successful do the rest? On a test client launch Terminal and issue this command: sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.mDNSResponder.plist sudo reboot now The mac should now reboot itself. Make sure you login as the local administrator before issuing the command. If you're new to the platform and you're being required to support it in your environment It might be advisable to enrol yourself on an approved Training Course? Antonio Rocco (ACSA)
-
My macs won't ping server but will ping server.prentonhigh.local
AntonioRocco replied to reggiep's topic in Mac
Hi This sounds like it could be one of two things or possibly both? Querying the hostname on the forward pointer and having it resolve to an IP address proves the forward lookup zone is configured. If it's returning the correct IP address then you know the zone is configured correctly. If you can verify forward queries return the correct information for all your servers then that's a good sign. Querying the IP address on the reverse pointer and having it resolve back to the known hostname proves the reverse lookup zone is configured. Doing the above queries using either the host, nslookup or dig commands basically 'qualifies' your DNS Service. Using ping is OK up to a point but it's not what I would use to troubleshoot DNS issues. If you're not seeing a successful return on a reverse pointer query then that can only be because: (a) There is no reverse zone configured (b) There are multiple reverse zones configured © DHCP Service is not configured as it should be? (d) DHCP Service and is handing out the wrong information regarding DNS and Domains? Another possibility is the main DNS Server (presumably your PDC?) is using it's own loopback address as the Primary DNS Server? In which case it won't resolve itself properly and potentially cause problems for successful profile discovery and access. Hope this helps? Antonio Rocco (ACSA) -
Hi "Any 'killer app' for Mac backup?" Yes, although it depends on how much you're prepared to spend? BakBone Software - Products Atempo - Data Management, Simplified. - Atempo Time Navigator Complete Product Listing - TOLIS Group, Inc. - The Backup and Recovery Experts CrashPlan - Automatic Online Backup Tri-BACKUP (from TED) Finally the one you mentioned: EMC Retrospect The version EMC have developed is a far cry from what you probably remember? It's more expensive as well. Of course you could forego all of the above if you're prepared to use the command line? If you are "rsync" or "ditto" scheduled shells via launchd or cron (still doable in 10.5) is also possible. An easier option that involves the least effort and no money would be to simply 'drag drop". Antonio Rocco (ACSA)
-
Hi "is it worth upgrading anything on it to get it running sweeter" I still have an iBook G3 500Mhz, 384MB RAM, 20GB HD with 10.4.11 installed which I still use. It's more than good enough to browse the web, a bit of emailing and some low level printing. I keep it because it has a lot of useful utilities that you can't get anymore and that won't run on anything else. However when compared to the current models it is very slow. I could upgrade the hard drive if I wanted and probably squeeze another 128MB of RAM but I don't think I would gain anything other than a hole in my pocket. I have to agree with GrumbleDook but I think you may struggle in getting anything for it? Let alone anything new? PC100 Modules is what your model takes so if you have some lying around re-use them. Not all PC100 Modules will work. As you know most hard drive manufacturers have stopped making PATA/IDE drives, so you may struggle getting hold of these too? If you've got any 40GB, 60GB drives hanging around in any old PCs somewhere you could use them. If you're going to upgrade the drive or even stick another one in you will need the original installer disks that came with it to reinstall everything. Or at the very least universal versions of 10.1, 10.2, 10.3 or 10.4. Your problem may then be the quality of the optical drive? Although if you have an external firewire caddy with an IDE interface you could transfer the current drive into it, install a new drive and use something like CCC to clone over. If I recall your particular model won't support drives larger than 128GB. "Minimum it needs is wireless if that is possible!" I think this is going to be your biggest problem. There may be a slot that can accept the first generation Airport card (11mbs) but I doubt it. Even if there was it would be hard to source the card anyway. They can be expensive because of their rarity. EBay is the only place I can think of? After this I suppose you're left with trying to source a 3rd-Party wireless card or dongle? As I recall there was only one that worked with macs at the time anyway. A D-Link DW112 (I think?). Sourcing one of these will probably be just as difficult and expensive? You may have to just go for a wired connection? Don't be tempted in trying to use any new wireless dongles/cards etc as the OS, hardware and bus speeds more than likely won't support them. To find out more about mac hardware you could use this: Mactracker "The geek in me would like to save it" Know what you mean. I don't like chucking anything away that still works! Antonio Rocco (ACSA)
-
Hi "Would it matter, if the old domain name and the new domain name are the same? It would only matter if they were different. If they have differed because you've changed it for a known reason then yes this could cause problems. One thing you should know is successful mac integration into an AD environment - amongst other things - is mostly about the 'health' of internal DNS Services. Macs require correctly resolving DNS on both the forward and reverse pointers. The reverse pointer is extremely important as that is how macs 'discover/access' home profiles. In other words your AD environment must have a Reverse Lookup Zone configured. It will be in your DNS Snap-in Module. Get this part of your environment right and things do go smoothly and what's more work - mostly. Internal DNS Services should be working correctly for AD to work optimally in any case. Another thing to remember is to avoid using .local as the basis for internal DNS Services. Not so much of a problem since 10.5.4 but can and still does cause slow log-ins as well as long binds. It can even cause macs to lose contact with the Domain Controller. Typically when binding Mac clients to Active Directory if it's taking longer than 2-3 minutes you have a problem somewhere? It should not take any longer than 20-30 seconds - a minute at the most. This may not necessarily be down to DNS although you should eliminate any lingering DNS issues as soon as possible. The bind delay could also be down to in-appropriate OU permissions and/or poorly structured and confused OUs. When binding you should only have to use an AD Account credentials that has authority for the Domain. The reason why you're being prompted to use the local admin account as well is because it's taking too long. Once you go beyond 5 minutes you've gone beyond the time sync value set by your KDC anyway. It's not surprising the whole thing fails thereafter. You do know there is an option to extend the default 5 minutes to 10 minutes don't you? This is done on your KDC. It will be in the Kerberos Account Policy either at the Local, Domain or Group level. Depends where you have it set. Can you actually resolve the PDC to itself on both pointers? Try not to use Ping as the only tool to resolve names to numbers. Can you do the same from a mac client? Use the host, nslookup and dig commands to do this. Is the DHCP Service 'pushing' out the correct information in terms of DNS Servers and Domain name? What happens if you try and resolve an assigned IP address given to a mac client on the reverse pointer? Antonio Rocco (ACSA)
-
Hi All BootCamp does is prepare a 'soft' partition as FAT32. It can only do this from the OSX environment. You can't create NTFS Volumes unless you're prepared to use the command line. The other way is to use a Windows Installer Disk. As you've found out. OSX can only read NTFS Volumes. There are 3rd-Party utilities that do allow writes. You have to be careful with this in case it 'breaks' Windows. You actually don't even need to use BootCamp. You could have reinstalled MacOSX and partitioned the internal drive as two partitions. One formatted HFS+ the other FAT32. Once OSX is installed you can insert a compatible Windows Installer, restart and hold down the 'C' key. It should boot into Windows from there. Once Windows is installed and running you should insert the Snow Leopard Installer Disk which will should AutoRun and install all the relevant Drivers for Sound, onboard networking, keyboard, trackpad bluetooth and anything else the officially supported OS needs. Supported Windows OS are listed when you first run BootCamp Officially Windows 7 is not currently supported. Install at your own risk. Windows 7 Beta worked fine for me (including sound) in Leopard (10.5). Until Apple say different I've not bothered installing it on any SL Client Macs. If you got 'stuck' at the Windows Install powering off and powering on again and holding down the 'alt' key (the one between the command key and the ctrl key) should have presented you with the option to reboot in OSX. Once there you could have ran the BootCamp Assistant again to firstly remove the Windows partition (effectively erasing it completely) and then creating it again. Antonio Rocco (ACSA)
-
Hi That's because Macs are DDNS aware on the forward pointer only. It's not their fault because that's how the OS works. What you see in Terminal is the reverse pointer record associated with the IP address. You have to manually clear these out as making the Ageing setting to 1 day does not necessarily do this. Renew the DHCP Lease afterwards by clicking the appropriate button in the Network Preferences Pane or simply Restart. On a client Mac look at the assigned IP address launch terminal and issue: host IPaddressofMac It will probably return at least one (if not more) reverse pointers that have been associated with that IP address previously. "macs still dont update the PTR records. Every windows client on site does, not a single mac does" This is not meant as a criticism but expecting macs to 'behave' like PCs makes no sense? Apple have implemented DNS & BIND fully since the beginning. AFAIK Microsoft have their own take on this which is not strictly the same? It's a shame the suggestions have not worked. What is interesting is at stodge1000's site binding using the command line worked. Yet at your site nothing. Clearly each Active Directory is unique. As such macs will find every flaw and weakness in that environment like nothing else. The trick is finding out what the weaknesses are? Of course this could all be rubbish and it might all get fixed in the next Software Update - 10.6.2 anyone? Yours is not a CC3/CC4 build is it by any chance? Antonio Rocco (ACSA)
-
You're almost there guys but not quite. Hope you're both well? You can't make com.apple.sidebars.plist a persistent setting (Always) it only 'works' if it's an Often setting. This is fine in most cases because network users generally won't have much of an idea they can restore the setting by going to the Finder Preferences Menu and changing the values from there. As we know this does not apply to everyone. The trick is how do we deny network users access to the Preferences selection from the Finder Menu yet still allow them access to the Menu? A simple solution could be to apply the Simple Finder MCX to the group. This might be too restrictive for most environments? First switch off the option to show the Shared View. This will amend the com.apple.sidebars.plist. Launch WorkGroup Manager and add the modified plist to the Group you're interested in. Make it an 'Often' setting. Next launch Terminal and issue this command: defaults write com.apple.finder ProhibitFinderPreferences -bool YES You have to restart the Finder for the setting to take full effect: killall Finder You can copy and paste the above into the Shell if you wish. This will add the ProhibitFinderPreferences value to the com.apple.finder.plist. Add this modified plist as an Always setting. If you're already managing aspects of the Finder there should be a com.apple.finder.plist already in the Manifests tab. Simply amend this by adding a New Key. In the Name Field key in: ProhibitFinderPreferences; in the Type Field select boolean; for the Value Field select True. Click Appy Now and Done. That should be it? To reinstate the setting on the local client you're working from issue: defaults delete com.apple.finder ProhibitFinderPreferences Restart the Finder again by issuing the same command as given above. There are other ways of doing this. You could use ARD for example and issue the above commands just once to all mac clients. This may not be advisable as you might want to leave the option available to local administrators? Some methods don't involve the mac at all. Modifying the DHCP Service (if Windows based) can/will achieve a similar result. Hope this helps? Antonio Rocco (ACSA)
-
Hi "the PTR records dont seem to update properly - so whatever name you give a client, in ARD it appears as another computer name, and if you start terminal it appears as the wrong name" This is because there are stale reverse pointer records hanging around that should be scavenged. In the Reverse Zones you should set the Ageing amount to 1 day or so. The default is 7 days. This aspect of Windows DNS/DHCP Services is also 'tied' in with WINS/NetBios support. When was the last time you had to support NetBios clients? Just because it's always been there and switched on does not mean it has to be used. I can't see how disabling the feature (DHCP > Advanced > disable NetBios over IP) can interfere with what client OS you currently have? - Assuming XP and above? I don't think the above has anything to do with your problem though? Are mac clients in the same sub-net as the main servers? You could test one mac client by assigning an IP address within the server subnet to see if that makes a difference? You could also add the PDC's IP address and hostname in /etc/hosts (use a terminal editor such as nano or pico etc - don't use the Finder) to see if that helps also. Again test with one client mac. Have you tried defining the TTL value to half the default amount yet? Hopefully this might help? Antonio Rocco (ACSA)
-
Hi Apple - Support - Discussions - Microsoft Office ... Antonio Rocco (ACSA)
-
Hi "I have absolutely no idea how to find the path /Network/Library/Fonts!" That's because it does not exist. You have create it first. Create a folder/directory on the Server. Call it whatever you like. Fonts is as good a name as anything. Place your Fonts into it. Launch Server Admin. Click on the Server Name and select File Sharing. Select the volume you created the folder in. Click the Browse tab. You should now see the created folder. Click Share. On the Share Tab select the Enable Automount option. From the resulting window make sure LDAPv3/127.0.0.1 is selected. Select Shared Library Folder. You should be prompted to authenticate using the diradmin account details. Leave the default permissions as they are. Hopefully that should work? There are three font locations on OSX 10.5: 1 /Users/Home/Library/Fonts 2 /Library/Fonts 3 /System/Library/Fonts Number 1 is where you should be placing any additional fonts. Fonts should be placed 'loose' within that folder. No nesting of fonts within folders for example. Fontbook places/moves fonts to this location Number 2 is where 3rd Party applications such as Microsoft Office generally places fonts. You can place additional fonts here as well although you should really use number 1 as it makes it easier to troubleshoot in case there's a problem. Leave Number 3 alone. Previous versions of the OS added to these locations with an additional Font location. This location was there to support the 'Classic' environment. Although the fonts were also available to OSX. If you have ARD you could simply copy the fonts over to mac clients simultaneously. Antonio Rocco (ACSA)
-
Hi xkcd - A Webcomic - Windows 7 Personally I quite like Vista. Antonio Rocco (ACSA)
-
Hi HodgeHi (hello Mark!) makes a good point. You would need to know both passwords (the old one as well as the new one) to defeat Keychain Manager. However this can be got around if you know what to do. You could enable Root and give it a completely different password as well. You can deny access to the Keychain Access application using Parental Controls (if a local 'managed' account) or a suitable MCX in WorkGroup Manager. If you can't be bothered to do this you could remove the whole of the Utilities folder and place it on the desktop of the local admin. From there create an encrypted disk image using DU. There would be no way anyone could access it then Not even if you used Target Disk Mode and selected the 'Ignore Permissions on this Volume' option. To reset a firmware password take out one of the RAM Modules. Restart the Mac and reset the Parameter RAM (PRAM) three times. Switch it off. Replace the RAM Module, switch it on as normal. If Mac suites have CCTV fitted it would be a fairly obvious thing to spot. Antonio Rocco (ACSA)
-
Hi @ mac_shinobi "Crack the admin accounts login credentials by using the single user mode" Enabling a firmware password would disable anyone's ability to access single user mode. Even this can be got around if you know what to do. However it would be pretty obvious catching students if they attempted it. It's not really something that can be done quickly if you've never done it before. " . . . using a cd to reset the local admin accounts password" Deny them access to the optical drive with the relevant managed preference. WGM > Group and/or Computer Group > Media Access. ". . . domain admin accounts over ride the local admin accounts afaik (correct me if I am wrong )" Good question! I'm not really sure myself? I don't think it's a question of local vs domain. Any admin account should work. For example I could create a mobile account (stored locally on a mac client) for an account that exists on Active Directory. User Profile gets downloaded to the local drive. I would then need to enable that account as a local admin using the default local admin account credentials to authenticate the action. Log out and log back in again to make it active. There would then be nothing stopping you from deleting the default local admin account. However you would need the local admin to allow this to happen. It's important therefore to 'secure' the local admin account as much as possible. You can apply a managed preference hiding the local admin account from view entirely. Antonio Rocco (ACSA)
-
Hi @ rush_tech "Can I just ask where is the wireless key visible on a MAC?" Keychain Passwords are visible in the Keychain Access application: /Applications/Utilities. Launch the application, select login in the left hand panel, select the password you're interested in (it should be listed) click the 'i' icon at the bottom or use command+i. Select the 'show password' option. You should be prompted to enter the local admin password as well as the option to either 'Always Allow'; 'Allow Once' or 'Cancel'. Antonio Rocco (ACSA)
