Mac user cannot logon to domain

We have a Mac user who successfully logs onto Windows domain at office in City1, but when he moves to City2, he can no longer logon (password field shakes).  He has a windows laptop that successfully logs on no matter which office he works in (and is able to access all shares, etc).  I am a Windows AD expert, but the only thing I know about Mac is how to spell it.

Any Mac administrators out there who can help with this one?  I'm sure it is simple, but I am just not seeing it.

Thanks!
Sudsybrew1Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

TMekeelCommented:
Are the offices on the same domain and connected via vpn?
In other words can the machines communicate with the DC while in City2?

You may not have setup a mobile profile (not the same as a roaming profile on Windows.)  Mobile profile allows the cached credentials to login outside of the office.

You may also not have selected allow authentication from any domain in the forest, and in that case it will only authenticate to the original DCs in the other domain (assuming the sites are same forest/different domain.)

Can you clarify the network setup in City1 and City2, and how they communicate with one another?
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Sudsybrew1Author Commented:
Thank you for the response.  Yes, the offices are on the same domain and are connected via VPN.  Windows laptops can move around freely with no issues, but the Mac cannot - is this solvable with the mobile profile (i.e., will he still be able to access shares, servers, etc)?

I am not sure if "allow auth from any domain in the forest" was checked, but would that matter if they are on the same domain?  Just trying to learn a little about Mac networking.

Thank you!
0
TMekeelCommented:
One more question sorry...which version of OS X? (Click the apple > about this mac)
The support for AD varies greatly with new to old.
Is the Mac using the same DNS servers as the Windows clients?
Can it ping the DC in City1 while at City2? (If you cant login at all I understand you cannot answer this question.)


is this solvable with the mobile profile (i.e., will he still be able to access shares, servers, etc)?
Perhaps, but technically speaking the mobile profile would allow him to login, not access shares.  So for example, if he were on a plane with no internet access, he could still login.  Without that type of profile the credentials are not cached, and it will allow local logins only.  Given the ability to login, if he could then access shares across the site to site VPN is a separate networking issue.


I am not sure if "allow auth from any domain in the forest" was checked, but would that matter if they are on the same domain?
It should not matter if it is one domain with a site to site tunnel. I'd guess he can't login with the mac using the domain credentials outside of the office due to the type of profile that was created.  

Do you have a local admin profile available to use?  If so you should be able to edit the domain profile settings using System Preferences.
0
Sudsybrew1Author Commented:
There were two problems creating this issue - the main problem was that we had not created the Mobile Account.  The other was that we were attempting to connect to an access point utilizing WPA2-Enterprise, so until we created the mobile profile, he could not authenticate with the access point - we had to purchase an external ethernet port for the initial logon.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Apple Networking

From novice to tech pro — start learning today.