Solved

Using Centrify for Windows group policy

Posted on 2013-01-30
9
1,317 Views
Last Modified: 2013-02-18
I was reading an article on this link:
http://www.centrify.com/directcontrol/directcontrol_architecture.asp

Actually I would like to have our Mac computers under control of windows AD GPOs.
the article states that I need :
- Installing the Centrify DirectManage tools and using Centrify Deployment Manager
but it does not say if It has to be installed on windows domain controller or on another system.

-Using Deployment Manager to install the Centrify DirectControl Agent on target systems and join them to Active Directory.

any prior configuration on Non-windows computers before installing the Centrify DirectControl Agent on them ?

Thank you.
0
Comment
Question by:jskfan
  • 4
  • 2
9 Comments
 
LVL 78

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 250 total points
ID: 38838641
It is installed on the client only, you will have to create an OU for centrify.
0
 

Author Comment

by:jskfan
ID: 38838801
Can you clarify it.
What to install on the client (Mac computers) and what to install in the DC.
0
 
LVL 78

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 250 total points
ID: 38838823
You install the client on the MAC and NOTHING on the DC
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:jskfan
ID: 38838841
the link says:
Deploying the Centrify Suite consists of two steps:

¦Installing the Centrify DirectManage tools and using Centrify Deployment Manager to discover network non-Windows systems in your environment
¦Using Deployment Manager to install the Centrify DirectControl Agent on target systems and join them to Active Directory

it is confusing
0
 

Author Comment

by:jskfan
ID: 38846454
any clarification based on the link , please?

how do the MAC specific settings become available in AD Group policy ?

thanks
0
 
LVL 62

Accepted Solution

by:
btan earned 250 total points
ID: 38850784
Extracted a couple of useful info and para to aid understanding...hope it helps

On UNIX, Linux and Macintosh computers, there is no equivalent to the Windows registry. The de-facto standard for configuration is through text-based configuration files. To enforce Active Directory's Group Policies on these non-Microsoft platforms, DirectControl creates a "virtual registry" to hold the Group Policy configuration settings that apply to that managed system and the users logging in to it.

For each configurable application that a policy applies to, DirectControl provides a specific mapping program that translates these virtual registry settings and updates the appropriate configuration file for that application with the settings defined by the policy.

On each DirectControl-managed computer, the DirectControl Agent is responsible for contacting Active Directory to determine the relevant policies and copying them down to a set of virtual registry files. These policy files are refreshed in the same way they are on Windows systems: when a user logs in, on computer restart, and at periodic intervals defined by Group Policy. Administrators can also update Group Policy on demand.

http://www.centrify.com/directcontrol/grouppolicy.asp

The Deployment Manager automatically detect Mac OS X systems within your environment and test them for readiness to join Active Directory, helping you identify and eliminate many common issues (such as DNS configuration problems) that slow down deployment of the Centrify DirectControl agent. Deployment Manager can then remotely install DirectControl on these Mac systems, automatically downloading the most current version for you from the Centrify website. You can also centrally update DirectControl on these systems as new releases become available.

The Centrify DirectControl for Mac OS X installation program is also provided in universal binary format, making it easy to deploy DirectControl on individual systems or across the enterprise.

Mac OS X workstations can be treated just like Windows workstations for access control purposes, permitting anyone with an Active Directory account to log in once the Mac has joined the domain. For those organizations, DirectControl's workstation mode streamlines installation using the same methodology to add a Mac workstation to an Active Directory domain as that used to add Windows workstations. The interactive installation program offers users the option to add the Mac in workstation mode. Remote installations can specify workstation mode through command-line parameters.

A major advantage of workstation mode is that the installation process has been streamlined. You do not need to install the Centrify Administrator's Console first. You simply install DirectControl on a Mac and it is automatically joined to Active Directory and appears as a computer object in Active Directory Users and Computers. During workstation installation, Macs are not added to a DirectControl Zone, but if you want to use patented Zone technology to limit access to Macs to a select set of users or groups, it is easy enough to install the Centrify Administrator Console and add those Macs to a Zone. You can have a mixture of Macs in workstation mode and standard mode in Active Directory, giving you the flexibility to apply tighter access controls to select systems as needed.

http://www.centrify.com/directcontrol/mac_os_x.asp


If you have ~30 min to spare, catch this video

http://www.centrify.com/resources/configuring-mac-os-x-using-windows-group-policy.asp
0
 

Author Closing Comment

by:jskfan
ID: 38904398
Thank you!!
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now