Improve company productivity with a Business Account.Sign Up


Active Directory vs. OS X Server 10 to manage Macs

Posted on 2016-08-31
Medium Priority
Last Modified: 2016-10-18
Hello - I would like to receive feedback from anyone who has managed both Mac OS X computers in an Active Directory and OS X Server domain environments please?  

I realize you can join Mac OS X computers to either Windows Active Directory or OS X Server Open Directory but am curious of the actual day to day management and "real life" experiences of how managing Macs in each of these two environment compares.

Any feedback and sharing experiences would be most appreciated!

Thank you
Question by:Rainman13
LVL 44

Accepted Solution

Adam Brown earned 500 total points
ID: 41778719
Macs can't be functionally managed by Active directory, so if you want to manage things like security settings or GUI appearance, you have to use the OS X Open Directory. You can bind Macs to an AD environment, but this really only allows you to log in to them using AD credentials, which can then be used to browse Windows based file shares. You would have to have a third party solution (which there are a few of) to manage settings on Macs using AD. If all you have is Macs, use OS X "Server". If you have a mix, you can decide which systems are more important to manage, or see if OS X Open Directory has plugins for managing Windows Computers. Just be aware that every attempt Apple has ever made at server solutions has been universally crappy. And Apple really doesn't care about that in the least, because they are not in the business of supporting businesses.

Author Comment

ID: 41778753
Thanks for your thoughts Adam and in this situation it will be an all Mac computer setup.  

OS X Server makes sense but like you mention on the flip side support resources, etc. can be costly to support.  AppleCare OS support plan for the "Select" plan starts at almost $6,000 for just 10 incidents which seems crazy.

A/D does provide some benefit as you mention also but it is limited.  

You are also seems Apple is just not as excited about as their customers in terms of having their devices run in a business setting.
LVL 15

Assisted Solution

by:Justin Pierce, CEH, CNDA
Justin Pierce, CEH, CNDA earned 500 total points
ID: 41779221
Hi Rainman13,

All hope is not lost. Your Macs are just computers (beautiful ones at that) and can run in AD environments just fine (I do it every day). That said, you do have to think differently when working with Macs in a Microsoft world, because other employees run Windows systems and use different programs to accomplish their tasks. However, since the inception of OS X, Apple has made these tasks much easier for us Mac people. Meaning, the common productivity suites that are used in business environments (MS Office) can be paralled with Apple's: Pages, Numbers, and Keynote (iWork). Each of these applications can import and export their counterpars documents, e.g. Pages imports/exports Word documents, Numbers imports/exports Excel spreadsheets, and Keynote imports/exports Power Point documents. I would suggest for the people that will be working on the Macs to use iWork over MS Office for Mac (leave the MS headaches for the PC crowd. Outlook..ugh, need I say more).

As for the AD part, the Mac personnel can connect to Wi-Fi using AD credentials, you already know that you can bind (not really needed for many Mac people), and using "Connect to Server" (CMD + K) to access files and folders (also accessed by AD credentials). All in all, if you really need to have your Macs act like PCs you might want to look at Thursby's ADmit Mac application.

That said, I like to manage my Macs with OS X Server, while letting them dip in the Windows environment with the things I said above. OS X Server allows me to restrict by groups (device or people) and keep the kids (I work at a K-12 school) from doing crazy things. In addition, with running the OS X Server I can manage and restrict my iOS devices with ease (not easily done with Windows MDM programs, and certainly not within the price point of $19.99).

Lastly, Apple does care about the business environment. They certainly understand that BYODs are more  common place now, and are tailoring their services accordingly. Remember Macs are Macs, and will operate as such. Apple will not mimic PCs and will not feel bad for ignoring the comments from MS users who hate that a Mac doesn't work like a Windows system. Also, there will always be polarized MS and Apple users, but for those of us that work in I.T., we know that it really comes down to perference (do you like driving a Ferrari or Lamborghini) so we drown out the noise of, "Windows are better than Macs because...". There's always a way to get things done on either system, you just have to have the will and want to accomplish the task(s).  

I hope this helps. Take care.
Get 10% Off Your First Squarespace Website

Ready to showcase your work, publish content or promote your business online? With Squarespace’s award-winning templates and 24/7 customer service, getting started is simple. Head to and use offer code ‘EXPERTS’ to get 10% off your first purchase.

LVL 32

Assisted Solution

nappy_d earned 500 total points
ID: 41779590
I manage both windows and macs very easily with AD.

Tools to look at:
  • great tool for OS X management with an interface for Windows admins.
  • if you do not have servers on site but want centralized management, this may be the tool for you

Checkout this post on Centrify and one of many others I've assisted with in my profile.

My final $0.02 on OS X for management is that depending on the size of your organization, OS X server does not offer redundancy for its LDAP implementation.  It's always one server and if/when it fails, potentially your company grinds to a halt.
LVL 32

Assisted Solution

serialband earned 500 total points
ID: 41780783
To manage Mac with AD, you need paid software such as Centrify or PowerBroker.

Macs can join AD for SSO authentication.  You can then use OD to manage them.  You can also manage them through command line or scripts.

Author Comment

ID: 41786750
Thanks to everyone for your thoughts and sorry for the delayed response.

We are reviewing the notes above and doing more research - will provide an update soon!

Author Comment

ID: 41786762
nappy_d - you mentioned working with Jump Cloud - would you recommend that over Active Directory?  If so why?

Our situation looks like it will be mostly Mac with little if any Windows computers on the network - it looks like JC has some benefits over Ad in that regard.
LVL 32

Expert Comment

ID: 41787589
I merely mentioned Jump Cloud for that exact reason. AD is great and has a lot of benefits that are too many to but as you point out, you have little if any Windows in your environment.

You still want centralized authentication and management which makes Jump Cloud a solution over OS X server for redundancy and systems management from anywhere.

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

The article explains the process to deploy a Self-Service password reset portal I developed a few years ago. Hopefully, it will prove useful to someone.  Any comments, bug reports etc. are welcome...
This is the conclusion of the review and tests for using two or more Password Managers so you don't need to rely on just one. This article describes the results of a lot of testing in different scenario's to reveal which ones best co-exist together.…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

608 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question