iMac Domain Computer Issue

Hi Experts!

I have an new iMac in the environment, i've given it a static IP on our network and then i've joined it to the domain using an administrator account. The problem i'm having is when I join the iMac to the domain it doesnt create a computer account for the iMac in Active Directory, I've tried dis-joining it and re-joining putting a new OU path for it place the Computer account in and that hasnt worked. I've also logged the call with Apple to investigate further. I had this issue on Mavericks and I still have it on Yosemite. I already 2 iMacs and Mac Book Pro in the environment which started on Mavericks and joined the domain fine with the computer account being created succesfully.

LVL 13
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Gary PattersonVP Technology / Senior Consultant Commented:
Not my area of expertise, but have you tried just manually creating the AD Computer account first, and then joining the iMac to the domain?
REITAuthor Commented:
Hi Gary,

Tried that and AD stated the computer already exists? but when I do a search of the entire directory/domain the machine doesn't appear.
Where are you looking in AD?  I think it places it into the default Computers OU or the OU the user account you use defaults to.
Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

"Tried that and AD stated the computer already exists? but when I do a search of the entire directory/domain the machine doesn't appear." When are you doing this search? After creating the computer record but before attempting to bind the machine to AD? If you pre-create the computer account and then bind the Mac, it should give the "already exists" error, but it still allows you to join it with the current computer (It's just a safety feature to avoid overwriting computer accounts). Or does the bind process make it disappear from search?

Put it this way, if you create the computer record manually, you should be able to search for it and find it before attempting to bind the Mac. Then approve the "already exists" join, and you should still be able to find it in a search. If not, I am not sure it's a Mac issue.
A few important questions to answer:

Are you using a .local domain?

Is IPv6 disabled? If not, while logged in as local admin on Mac, open Terminal, type "sudo networksetup -setv6off Ethernet" and enter the admin password when prompted.

Are you using a eead-only DC?

Is the Mac's Unique AD-Name less than 16-Characters?

Also, DNS can play a part. How to check that:
REITAuthor Commented:
I've searched the entire directory in AD. Also i dis-joined it from the domain, then prestaged the computer account, then joined the iMac to the domain using a different domain admin account and the message did come up stating the computer already exists and I then pressed ok. BUT when you check the computer account in AD there is no information for it like the Operating System the computer has.

I very highly doubt this is an issue in our domain as we have joined 2 iMacs and 1 Mac Book pro the domain in the same way and the computer account is created when the machines are joined to the domain.

No we dont use .local

We don't use IPV6 so this is irrelevant

No we aren't using an RoDC

Yes the iMac's Hostname is less than 16 characters

DNS is fine.
REITAuthor Commented:
Also i can login to the iMac fine and i've asked 3 other users on our domain to login and it logs in fine?!?

just concerned in terms of the secure channel between this iMac and the domain because the computer account still doesnt have any info on the iMac which isn't looking healthy.
Gary PattersonVP Technology / Senior Consultant Commented:
Any chance that this system has a duplicate SID with another system in the domain?  Was it cloned from another system that was already joined to the domain?  If so, then computer name isn't what is tripping that "duplicate" error.

I'd try to unbind from AD, delete the computer account, allow time for AD replication, then attempt to re-bind.  You should get a clean SID generated that way.

This article explains how to unbind/rebind from AD.

If you keep getting Duplicate errors, you probably want to figure out how to display the objectSID assigned to this system and then search AD by that objectSID to see what system is conflicting.  Maybe you can unbind/delete account/rebind that system to get a new SID - or maybe it is something no longer in use and you can just delete it.

You can use PowerShell to search AD for a specific SID:

> [ADSI]"LDAP://<SID=S-1-5-21-500000003-1000000000-1000000003-1001>"

Wish I could be more help - just not familiar enough with AD integration on OSX to provide much specific info.
Thanks for the detailed answers. That all sounds right, but I mentioned IPv6 because of some reports that having it on when not needed interferes with AD binding. So, for the fun of it, try deleting the account in AD, run the command to disable IPv6, and try rebinding.

It also might be helpful to run the following commands on the client in question and another similar Mac showing the correct computer account info:  "dsconfigad -show" and "id [any AD username]"
and compare the results. Any differences (other than ones which should be different) may help determine what's going wrong.

If still no joy, try deleting the account again in AD and manually binding the client:

sudo dsconfigad -a computername -u [ADadminname] -ou "CN=Computers,DC=domain,DC=org" -domain
(Note: You may need dsconfigad options for your setup. See the dsconfig man page for all the options available - "man dsconfigad" in Terminal)
You should receive a Password: prompt. First put in the password for the local admin account you’re using.
Next, you’ll get a Network Password: prompt. Put in the password for your AD account that has binding rights.
You should then see: "Computer was successfully added to Active Directory"
Test as per usual--

By the way, this all assumes you're comfortable with command line on the Mac, and you could definitely be doing this remotely via SSH instead of needing to be in front of the computer. Apple Remote Desktop is also an excellent (and cheap) tool for managing a fleet of Macs remotely.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
REITAuthor Commented:
I removed the iMac, deleted the prestaged computer account in AD, then waited 20 mins, renamed the iMac to a different hostname, then re-binded it to the domain and still no computer account.

Not really comfortable with command line on the iMacs to be honest!! Definitely not having fun either!
No better time than the present to expand your skill set!
Nothing I posted could mess anything up, but at minimum, run "dsconfigad -show" in the Terminal (or via SSH) on the Mac in question and one which has the correct AD account to compare. It is only a "show me the AD configuration" command, no worries, no danger.
REITAuthor Commented:
Tried it again today delete other computer account I created manually, then created a new one, renamed the iMac's hostname and then Dis-joined the iMac, waited 10 mins, re-joined with the new hostname, still didnt get any information pulling through on AD. I then disabled the account and then couldnt login to the iMac which means it is definitely communicating with the iMac. i will be happy with this for now.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Apple OS

From novice to tech pro — start learning today.