iMac Domain Computer Issue

Posted on 2014-10-29
Last Modified: 2014-10-31
Hi Experts!

I have an new iMac in the environment, i've given it a static IP on our network and then i've joined it to the domain using an administrator account. The problem i'm having is when I join the iMac to the domain it doesnt create a computer account for the iMac in Active Directory, I've tried dis-joining it and re-joining putting a new OU path for it place the Computer account in and that hasnt worked. I've also logged the call with Apple to investigate further. I had this issue on Mavericks and I still have it on Yosemite. I already 2 iMacs and Mac Book Pro in the environment which started on Mavericks and joined the domain fine with the computer account being created succesfully.

Question by:Rizzle
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 2
  • +1
LVL 35

Assisted Solution

by:Gary Patterson
Gary Patterson earned 100 total points
ID: 40411400
Not my area of expertise, but have you tried just manually creating the AD Computer account first, and then joining the iMac to the domain?
LVL 13

Author Comment

ID: 40411409
Hi Gary,

Tried that and AD stated the computer already exists? but when I do a search of the entire directory/domain the machine doesn't appear.
LVL 29

Expert Comment

ID: 40412056
Where are you looking in AD?  I think it places it into the default Computers OU or the OU the user account you use defaults to.
Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

LVL 10

Assisted Solution

schaps earned 400 total points
ID: 40412279
"Tried that and AD stated the computer already exists? but when I do a search of the entire directory/domain the machine doesn't appear." When are you doing this search? After creating the computer record but before attempting to bind the machine to AD? If you pre-create the computer account and then bind the Mac, it should give the "already exists" error, but it still allows you to join it with the current computer (It's just a safety feature to avoid overwriting computer accounts). Or does the bind process make it disappear from search?

Put it this way, if you create the computer record manually, you should be able to search for it and find it before attempting to bind the Mac. Then approve the "already exists" join, and you should still be able to find it in a search. If not, I am not sure it's a Mac issue.
A few important questions to answer:

Are you using a .local domain?

Is IPv6 disabled? If not, while logged in as local admin on Mac, open Terminal, type "sudo networksetup -setv6off Ethernet" and enter the admin password when prompted.

Are you using a eead-only DC?

Is the Mac's Unique AD-Name less than 16-Characters?

Also, DNS can play a part. How to check that:
LVL 13

Author Comment

ID: 40412745
I've searched the entire directory in AD. Also i dis-joined it from the domain, then prestaged the computer account, then joined the iMac to the domain using a different domain admin account and the message did come up stating the computer already exists and I then pressed ok. BUT when you check the computer account in AD there is no information for it like the Operating System the computer has.

I very highly doubt this is an issue in our domain as we have joined 2 iMacs and 1 Mac Book pro the domain in the same way and the computer account is created when the machines are joined to the domain.

No we dont use .local

We don't use IPV6 so this is irrelevant

No we aren't using an RoDC

Yes the iMac's Hostname is less than 16 characters

DNS is fine.
LVL 13

Author Comment

ID: 40412752
Also i can login to the iMac fine and i've asked 3 other users on our domain to login and it logs in fine?!?

just concerned in terms of the secure channel between this iMac and the domain because the computer account still doesnt have any info on the iMac which isn't looking healthy.
LVL 35

Expert Comment

by:Gary Patterson
ID: 40413124
Any chance that this system has a duplicate SID with another system in the domain?  Was it cloned from another system that was already joined to the domain?  If so, then computer name isn't what is tripping that "duplicate" error.

I'd try to unbind from AD, delete the computer account, allow time for AD replication, then attempt to re-bind.  You should get a clean SID generated that way.

This article explains how to unbind/rebind from AD.

If you keep getting Duplicate errors, you probably want to figure out how to display the objectSID assigned to this system and then search AD by that objectSID to see what system is conflicting.  Maybe you can unbind/delete account/rebind that system to get a new SID - or maybe it is something no longer in use and you can just delete it.

You can use PowerShell to search AD for a specific SID:

> [ADSI]"LDAP://<SID=S-1-5-21-500000003-1000000000-1000000003-1001>"

Wish I could be more help - just not familiar enough with AD integration on OSX to provide much specific info.
LVL 10

Accepted Solution

schaps earned 400 total points
ID: 40413183
Thanks for the detailed answers. That all sounds right, but I mentioned IPv6 because of some reports that having it on when not needed interferes with AD binding. So, for the fun of it, try deleting the account in AD, run the command to disable IPv6, and try rebinding.

It also might be helpful to run the following commands on the client in question and another similar Mac showing the correct computer account info:  "dsconfigad -show" and "id [any AD username]"
and compare the results. Any differences (other than ones which should be different) may help determine what's going wrong.

If still no joy, try deleting the account again in AD and manually binding the client:

sudo dsconfigad -a computername -u [ADadminname] -ou "CN=Computers,DC=domain,DC=org" -domain
(Note: You may need dsconfigad options for your setup. See the dsconfig man page for all the options available - "man dsconfigad" in Terminal)
You should receive a Password: prompt. First put in the password for the local admin account you’re using.
Next, you’ll get a Network Password: prompt. Put in the password for your AD account that has binding rights.
You should then see: "Computer was successfully added to Active Directory"
Test as per usual--

By the way, this all assumes you're comfortable with command line on the Mac, and you could definitely be doing this remotely via SSH instead of needing to be in front of the computer. Apple Remote Desktop is also an excellent (and cheap) tool for managing a fleet of Macs remotely.
LVL 13

Author Comment

ID: 40413275
I removed the iMac, deleted the prestaged computer account in AD, then waited 20 mins, renamed the iMac to a different hostname, then re-binded it to the domain and still no computer account.

Not really comfortable with command line on the iMacs to be honest!! Definitely not having fun either!
LVL 10

Expert Comment

ID: 40413331
No better time than the present to expand your skill set!
Nothing I posted could mess anything up, but at minimum, run "dsconfigad -show" in the Terminal (or via SSH) on the Mac in question and one which has the correct AD account to compare. It is only a "show me the AD configuration" command, no worries, no danger.
LVL 13

Author Comment

ID: 40416101
Tried it again today delete other computer account I created manually, then created a new one, renamed the iMac's hostname and then Dis-joined the iMac, waited 10 mins, re-joined with the new hostname, still didnt get any information pulling through on AD. I then disabled the account and then couldnt login to the iMac which means it is definitely communicating with the iMac. i will be happy with this for now.

Featured Post

Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SOA*.tmp files 2 180
Playing HDR x265 HEVC 10bit movie on iPhone 7Plus ? 2 118
Migration email from Entourage to AOL 20 42
Apps for MACPRO 6 45
In this article we will discuss all things related to StageFright bug, the most vulnerable bug of android devices.
Today, still in the boom of Apple, PC's and products, nearly 50% of the computer users use Windows as graphical operating systems. If you are among those users who love windows, but are grappling to keep the system's hard drive optimized, then you s…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question