MCX and nested groups

Just wondering if anyone has tried nested groups with Managed client.

I have user joe in group "x". Group "x" is a member of group "y". Group Y has preferences defined in WGM. When Joe logs in he should get a list of workgroups he is in (as long as preferences are defined in both). Instead he is logged right into group x. He does not have remember group set.

Going in via the finder I see that his permissions for file/folder access work correctly so wondering does nested groups work only with file access and not with Manage Cilent?

Posted on Aug 15, 2005 7:04 AM

Reply
1 reply

Aug 15, 2005 4:59 PM in response to Nathan Forrest

We have played with this fairly extensively and found it simply does not work the way Apple hoped it would (regarding MCX) and it is basically only good for file/folder permissions. Groups do not inherit preferences (although I'm told this WILL be working soon).

I had my friendly local Apple Service Engineer with me at the time and he suggested an interesting workaround (one that I hadn't thought of): You can use the computer level preferences (the third tab with the two boxes) to create an "uber" group of base permissions leaving you with much less work to create the groups. Before we did this we had to essentially duplicate each user groups list of allowed applications. Now we have a "base" list of allowed apps listed for the Guest computers (which is just about all the computers on the network) and we only need to specify a few "specialty" apps in each of the user groups (we are using a whitelist approach, obviously).

I did not realize the prefs would be additive like that, but they are, AND you can add some more prefs per user without conflict.

One last comment, you can specify access if you are managing prefs at the computer level. For example, we have a "Teacher" computer level group because we don't want any app restrictions for the staff (we are a HS). You can specify the teacher user group are the only ones who can log in to the teacher computer group, just in case a student grabs a teacher machine and tries to log in. Not huge security, but a nice little extra from MCX!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

MCX and nested groups

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.