10 Replies Latest reply: Aug 18, 2007 9:14 AM by Bruce Carillon1
Bruce Carillon1 Level 1 (105 points)
We have a 2003 AD network. I have successfully bound all Macs and the OS X Server to the AD. Users login and validate against AD on their Macs. That all works great!

Now, I want to use OS X Server to control users and groups with Workgroup Manager. I really don't have any idea where to start. The server is bound to AD and the server software has been installed and updated. Is there a document that offers step-by-step instructions for what to do next? Any tips or links to documents that would help would be greatly appreciated.

I would also consider hiring a consultant to walk me through it...


PowerMac G5, Mac OS X (10.4.10)
  • FL_MacTech Level 2 (230 points)
    You might want to check here for somebody you could hire.
  • Camelot Level 8 (46,665 points)
    You can easily use Workgroup Manager to edit Active Directory records.

    When in Workgroup Manager the little icon above the accounts list shows you the directory you're viewing. Set that (if it isn't already set) to your Active Directory domain. You'll see the directory accounts and can change them just as you world any other accounts.

    The limitation is that you cannot create new user accounts via Workgroup Manager - that has to be done with Microsoft's tools on a Windows machine.
  • criss Level 3 (995 points)
    go to www.bombich.com/mactips/activedir.html

    theres a whole document there on just what your doing, i do the same for my network
  • Bruce Carillon1 Level 1 (105 points)
    Thanks for the replies...

    My first attempt to do this resulted in me being able to see AD users & groups but when I tried to apply settings to restrict access to certain System Preferences it would allow me to apply them. I always got an error message.

    I have read the Mike Bombich white paper and get lost in a few of the steps along the way.

    If that's my best option I will continue to try it... otherwise I'm open to working with someone over the phone or in person. I called a few consultants from the Apple Consultant list and have had no reponse.

  • Camelot Level 8 (46,665 points)
    I always got an error message.

    And that error message is...?

    Knowing the error message would go a long way to help track down the issue.

    The obvious one is whether you have permission to edit the directory records, which should be apparent from the error message.
  • Bruce Carillon1 Level 1 (105 points)
    Error -14140
  • Bruce Carillon1 Level 1 (105 points)
    Okay, I have now gotten a bit further...

    Both the server and client are "bound" to AD. In WM I have set up a group in my LDAPv3/ that includes one user selected from our active directory. I then select Preferences and then make a few changes etc. I click save and done and get no errors.

    At a client machine I log in as that user and check to see if any of the preference controls are in place. They are not.

    So what should I check now? Thanks!!
  • Bruce Carillon1 Level 1 (105 points)
    Still closer yet...

    If I log into the server using the AD account that I used to set up the server, I am able to control prefs.

    So, I then added that user to the group and had them log into a client machine. Prefs are not controlled. So it appears the client is not receiving the WM controls for the group/user.

    How should I troubleshoot this? Thanks
  • costicladop Level 1 (115 points)

    In order to achieve user management for AD accounts, you'll have to setup Directory Access on clients to use LDAP and point to your OD master where you specified user management. This way, client macs will be bound to AD and also to OD. In Directory Access, make sure Search path has AD before OD.

    This should do the trick

    Message was edited by: costicladop
  • Bruce Carillon1 Level 1 (105 points)
    Exactly, that works! Thanks