?
Solved

Group Rights for AD users on Macs do not apply while off network

Posted on 2013-12-04
7
Medium Priority
?
270 Views
Last Modified: 2014-03-04
I have my Macs bound to AD and have staff user groups set to be able to administer the Macs as a part of the binding.  Users create a mobile profile as well.

When on the network they have admin rights to the local machine.  When they go home they can log in but the admin rights go away.

Any suggestion on how to correct this?  I am used to Windows PCs just holding your rights while on or off the network and am not too familiar with the Macs rules of operation.
0
Comment
Question by:GCISDEngineer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 39

Accepted Solution

by:
Aaron Tomosky earned 750 total points
ID: 39697332
Unjoin, remove local user accounts except one for emergency admin stuff, install free centrify, join using centrify.

You must have a local user with the same name or mobile profiles setup to even be able to login off network.
0
 
LVL 32

Expert Comment

by:nappy_d
ID: 39697939
Can you post a screenshot of your group settings for admin rights in your Directory Utility?  I am assuming this is where you have set your group admin rights.
0
 

Author Comment

by:GCISDEngineer
ID: 39698455
nappy_d Here is the Directory Utility information. Let me know if you see any issues.

Aaron, I am looking at Centrify as well but that may mean rethinking the entire image process.  We currently use Deploy Studio to join to the domain as a part of the imaging process and I am unsure how they would work together. Of course we would rather have fewer utilities working on the machine but I am open to trying Centrify.  It looks pretty good.

I will report back soon.
Screen-Shot-2013-12-05-at-9.13.2.png
Screen-Shot-2013-12-05-at-9.13.3.png
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 39698526
The main issue I had with osx built in join is it doesn't store password hashes for off network logins. Basically that makes it unusable on laptops unless you do the whole mobile profile syncing mess.
0
 

Author Comment

by:GCISDEngineer
ID: 39903135
After months searching I must say sorry,  I have found no real answer to the issue.  Centrify does cover the issue the best.  I thnk we may look at the full  product.
0
 

Author Closing Comment

by:GCISDEngineer
ID: 39903139
The solution works but involves a third party product.  There is no solution that I have found natively in the Mac AD binding.
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 39903552
FYI the free centrify does the joining and login cachich you need
0

Featured Post

Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
An article on effective troubleshooting
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question