Big Sur troubles with Active Directory
I state that in our company there are three different domains
corp.mydomain.com (mydomain.com is the external address)
mydomain2.com
corp.mydomain3.com
I have "almost" the same problem reported at this link
https://discussions.apple.com/thread/252893707
Computers used for testing:
MacBook Pro 13' 2017
iMac pro 27' Retina 5K 2017
Both with Big Sur 11.5.2.
Trying the binding on mydomain2.com things seem to work
- the domain in the login options of the system preferences appears correctly with capital letters (MYDOMAIN2)
- I can modify the various options of "Utility Directory (UD)".
- navigate the "Active Directory/MYDOMAIN2/All Domains" with the "directory editor" of UD
- the network users connect correctly and create their Home directories.
- at reboot everything continues to work properly (or so it seems)
...But if I try to bind with corp.mydomain.com
the domain in the login options appears with lowercase letters (mydomain), which is wrong in my opinion, and initially seems to work at least until I try to change any option of UD ("Create mobile account at login" and/or" Allow administration by:..." ) and save the changes or restart the computer .
At this point in the login options appears a second domain in uppercase (MYDOMAIN) with the same problems reported in the discussion that I cited previously, so summarizing ...
- in the login options of the system preferences appear two domains one in lower case and one in upper case
- I can modify the various options of "Utility Directory (UD)", but they seem to be a cause (or at any rate a concurrent cause) of the problem
- after the reboot I can add the "new" domain (the one in uppercase) to the "Authentication Search policy" but I CANNOT browse the "Active Directory/MYDOMAIN/All Domains" with the "directory editor" of UD, and I get a popup reporting the error "Connection to the directory server failed (2100)"
- network users do NOT connect or create their home directories.
- at the reboot the tiny domain disappears from the Login Options but remains in the "Authentication Search policy" and "Contacts" of UD
Unfortunately I can't bind computers to mydomain2.com or corp.mydomain3.com both domains will be migrated to corp.mydomain.com within few months, and also I have limited administrative rights on corp.mydomain3.com.
PS. I apologize for my bad English, and I hope to have been sufficiently clear.