Group Rights for AD users on Macs do not apply while off network

I have my Macs bound to AD and have staff user groups set to be able to administer the Macs as a part of the binding.  Users create a mobile profile as well.

When on the network they have admin rights to the local machine.  When they go home they can log in but the admin rights go away.

Any suggestion on how to correct this?  I am used to Windows PCs just holding your rights while on or off the network and am not too familiar with the Macs rules of operation.
GCISDEngineerAsked:
Who is Participating?
 
Aaron TomoskySD-WAN SimplifiedCommented:
Unjoin, remove local user accounts except one for emergency admin stuff, install free centrify, join using centrify.

You must have a local user with the same name or mobile profiles setup to even be able to login off network.
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
Can you post a screenshot of your group settings for admin rights in your Directory Utility?  I am assuming this is where you have set your group admin rights.
0
 
GCISDEngineerAuthor Commented:
nappy_d Here is the Directory Utility information. Let me know if you see any issues.

Aaron, I am looking at Centrify as well but that may mean rethinking the entire image process.  We currently use Deploy Studio to join to the domain as a part of the imaging process and I am unsure how they would work together. Of course we would rather have fewer utilities working on the machine but I am open to trying Centrify.  It looks pretty good.

I will report back soon.
Screen-Shot-2013-12-05-at-9.13.2.png
Screen-Shot-2013-12-05-at-9.13.3.png
0
Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

 
Aaron TomoskySD-WAN SimplifiedCommented:
The main issue I had with osx built in join is it doesn't store password hashes for off network logins. Basically that makes it unusable on laptops unless you do the whole mobile profile syncing mess.
0
 
GCISDEngineerAuthor Commented:
After months searching I must say sorry,  I have found no real answer to the issue.  Centrify does cover the issue the best.  I thnk we may look at the full  product.
0
 
GCISDEngineerAuthor Commented:
The solution works but involves a third party product.  There is no solution that I have found natively in the Mac AD binding.
0
 
Aaron TomoskySD-WAN SimplifiedCommented:
FYI the free centrify does the joining and login cachich you need
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.