Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Big Sur troubles with Active Directory

I state that in our company there are three different domains


corp.mydomain.com (mydomain.com is the external address)

mydomain2.com

corp.mydomain3.com


I have "almost" the same problem reported at this link

https://discussions.apple.com/thread/252893707


Computers used for testing:

MacBook Pro 13' 2017

iMac pro 27' Retina 5K 2017

Both with Big Sur 11.5.2.

Trying the binding on mydomain2.com things seem to work

  1. the domain in the login options of the system preferences appears correctly with capital letters (MYDOMAIN2)
  2. I can modify the various options of "Utility Directory (UD)".
  3. navigate the "Active Directory/MYDOMAIN2/All Domains" with the "directory editor" of UD
  4. the network users connect correctly and create their Home directories.
  5. at reboot everything continues to work properly (or so it seems)


...But if I try to bind with corp.mydomain.com

the domain in the login options appears with lowercase letters (mydomain), which is wrong in my opinion, and initially seems to work at least until I try to change any option of UD ("Create mobile account at login" and/or" Allow administration by:..." ) and save the changes or restart the computer .


At this point in the login options appears a second domain in uppercase (MYDOMAIN) with the same problems reported in the discussion that I cited previously, so summarizing ...


  1. in the login options of the system preferences appear two domains one in lower case and one in upper case
  2. I can modify the various options of "Utility Directory (UD)", but they seem to be a cause (or at any rate a concurrent cause) of the problem
  3. after the reboot I can add the "new" domain (the one in uppercase) to the "Authentication Search policy" but I CANNOT browse the "Active Directory/MYDOMAIN/All Domains" with the "directory editor" of UD, and I get a popup reporting the error "Connection to the directory server failed (2100)"
  4. network users do NOT connect or create their home directories.
  5. at the reboot the tiny domain disappears from the Login Options but remains in the "Authentication Search policy" and "Contacts" of UD


Unfortunately I can't bind computers to mydomain2.com or corp.mydomain3.com both domains will be migrated to corp.mydomain.com within few months, and also I have limited administrative rights on corp.mydomain3.com.


PS. I apologize for my bad English, and I hope to have been sufficiently clear.


Posted on Aug 23, 2021 7:45 AM

Reply

Similar questions

6 replies

Sep 7, 2021 7:14 AM in response to Old Toad

Sorry Old Toad if I'm only responding now but, lucky for me, I took a couple of weeks off (I really needed it).


I preferred to restart with a new clean Big Sur installation, just to be sure...

Here is the report after the first reboot from the bind , I hope it will be useful, we didn't find any useful data to solve the problem.


Aug 24, 2021 9:09 AM in response to Cesare Cerutti

To get an idea of you current setup download and run Etrecheck. Etrecheck is a diagnostic tool that was developed by one of the most respected users here in the ASC and recommended by Apple Support  to provide a snapshot of the system and help identify the more obvious culprits that can adversely affect a Mac's performance.


IMPORTANT:

Before running Etrecheck assign Full Disk Access to Etrecheck in the Etrecheck's Privacy preference pane so that it can get additional information from the Console and log files for the report:


Also click and read the About info to further permit full disk access.



Copy the report



and use the Additional Text button to include the report in your reply.



Then we can examine the report and see if we can determine what might be causing the problem. Also print out the report for your IT personnel to look at.

Big Sur troubles with Active Directory

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.