Solved

Mac OS X 10.7.5 and Active Directory

Posted on 2013-06-03
7
1,074 Views
Last Modified: 2013-06-23
We are a windows environment and trying to integrate macs into our network environment.  I have followed some instructions from this site, but nothing I do seems to work.  We keep getting Network accounts unavailable and are not able to log in with network credentials if there is no local account on the mac book.  I have tried to unbind and bind again, checked all the advanced network settings as recommended in some of the posts.   We do have a mac server and we have that listed in the Directory Utility as well as the windows network. I have added a preferred dns server and allow administration by domain admins, etc. under Directory Utility.

We do have a mac server - do I need to add something to this server in order to get this to work?  I have not set up a mac server at all and know nothing about it so any help would be greatly appreciated.
0
Comment
Question by:manch03
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
7 Comments
 
LVL 28

Expert Comment

by:jhyiesla
ID: 39218699
I don't have a Mac server in my environment so I'm not sure if that's causing an issue or not. However, mostly I do what you've done. I go into the directory utility from the Users and Groups system preferences window and in the Active Directory settings I put in my domain and forest -we have only one - and I choose to bind. The only setting that I change is the one to create the mobile login account. This is handy as it will allow your users to get into the Mac even if it's not on the network.

Do make sure that in the Administrative tab you have the Allow Authentication from any domain in the forest checked.

Also make sure that you do NOT have local Mac users with the same user ID as Domain ones as OS X will default to local users first if you don't specify your domain name in front of the user ID.

Something else you might try is in the Login options of the Users and groups preference screen check Display login window as : Name and Password. This shouldn't be necessary if the Mac is properly bound to AD, but still give it a shot and have your users try this as their username:  DomainName\UserName.  If they get on OK, this would confirm binding to AD successfully. If not, then either AD isn't doing something it should or the Mac server, if it's running OD, could be messing something up and I really don't have any working knowledge of that.

Check in ADUC to see that the Mac is there.  And if you unbind and then rebind, check in ADUC first to make sure that the Mac does get completely removed.  You can also use third party binders, but typically I haven't needed to use these since 10.7.x.
0
 
LVL 28

Expert Comment

by:jhyiesla
ID: 39218702
Forgot to also say, once domain user gets successfully logged into the Mac, check in Users and groups to see if they are showing successfully - they probably are, but it's a place to check.

Depending on the speed of your network, I've seen it take up to 30 seconds for the network to become available.
0
 
LVL 39

Accepted Solution

by:
Aaron Tomosky earned 300 total points
ID: 39219087
Don't join using the built in stuff. Dont gave any local users the same as AD users. Download and install the free centrify client, use that to join.

After you login once with a domain user it will cache the hash of their password allowing you to login offline
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:manch03
ID: 39229997
The mac's are not showing up in the AD even though it says they are bound to the AD.  It is only the Lion operating system that we are having this issue with.  The older mac's do not have a problem showing up in the AD.  We did download the centrify client and it seems to work well, but still not showing up in the AD.
0
 
LVL 28

Assisted Solution

by:jhyiesla
jhyiesla earned 200 total points
ID: 39230023
If OS X is saying that the binding is good - green light - then you should be able to see them in AD.  Is it possible that they are getting put into an OU or folder where you don't expect them to be placed?
0
 
LVL 28

Expert Comment

by:jhyiesla
ID: 39230032
Also, make sure you know the computer name of the Mac. I just checked mine and the computer name showing in the Sharing System Preferences is what I see in AD.
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 39230041
for centrify you first unbind in osx and clear out the computer from ad if it exists. install centrify, then use centrify to join. osx does not give a green light, it's all through centrify.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question