Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Cannot Join OS X Lion to Active Directory 2003

Hi,


I am unable to join a mac mini recently upgraded to OS X Lion to Active Directory 2003. Everytime I try to join, I get the following error: authentication server encountered an error while attempting the requested operation.


I was able to re-join an OS X Lion server to AD 2003 as it was joined to the domain before upgarding to Lion. I had to rejoin as it did not communicate properly with AD after the upgrade. But, it was no issue. The mac mini that will not joing the domain, but just errors out. Usually, with Snow Leopard, when it would not join, it was something simple (time off, wrong username/password, etc...). Snow Leopard also gave much more helpful error messages that actually told you what the problem was. Lion only seems to give the generic error that is of no help.


Anyone have any ideas on how to fix? Thanks in advance!


Thanks,


Kyle

Posted on Jul 29, 2011 12:43 PM

Reply
44 replies

Aug 9, 2011 4:08 AM in response to ragenkagen

I've been wrestling with this all morning.


I've seen various suggested fixes, but what's (partially) worked for me is repairing disk permissions in Disk Utility. I was then able to bind to the Active Directory domain. Network browsing still seems a little hit and miss, but I'm now able to access shares and the like and my AD permissions seem correct.

Aug 14, 2011 6:37 PM in response to ragenkagen

I also ran into this issue but managed to get around it.


Normally in Directory Utility you would bind to the domain: e.g company.com.au


When I was binding to my OD server I thought, what the heck, I'll try binding directly to a domain CONTROLLER and it worked like a charm. Obviously far from ideal but at least now I can login with my AD credentials and test things properly.


I bound to the domain through System Preferences rather than Directory Utility. System Preferences -> Login Options -> Network Account Server "Join" button.


I successfully connnected to server.company.com.au (which is a 2003 Domain Controller)


Hope this helps some people.

Aug 16, 2011 6:05 AM in response to AussieAppleUser

Thank you both for your suggestions. I repaired disk permissions and also tried pointing it directly at the PDC, but still cannot join AD...I do not know if it is the way our AD environment is structured or what.


Also, I started having issues with the one that I was able to join, it for some reason keeps dropping of the domain and losing connection with the domain, so that one does not even seem to work right.

Aug 23, 2011 1:40 AM in response to ragenkagen

It seems you are not the only one that cannot join to a Active Directory Domain. I am having the same issues. I have tried all of the usual -- reset file permissions from Command-R at startup, etc. I know the settings work as I have Snow Leopard working just fine. Lion simply doesn't want to play nice. This is the error I am getting:


Aug 23 01:16:24 mysystem System Preferences[544]: -[ODCAddServerSheetController handleOtherActionError: gotError: Error Domain=com.apple.OpenDirectory Code=5202 "Authentication server encountered an error while attempting the requested operation." UserInfo=0x000000000 {NSLocalizedDescription=Authentication server encountered an error while attempting the requested operation., NSLocalizedFailureReason=Authentication server encountered an error while attempting the requested operation.}, Authentication server encountered an error while attempting the requested operation.


I have used the same settings as use with SnowLeopard to no avail. I've even turned the OpenDirectory logging output to debug and nothing is jumping out as to what is going on. Has anyone else has success bypassing this error?

Aug 29, 2011 7:16 PM in response to ragenkagen

I am getting this same issue - every time I try to bind I get the "Authentication Server encountered an error while attempting the requested operation." error - I have tried different apsswords etc with no joy - I tried rebooting and repairing permissions as well, still with no joy.


We have also tried binding using the System Preferences method (though login items), Using Directory Utility and via Terminal.

Aug 30, 2011 1:25 PM in response to hitman23vt

Does anyone from Apple read the forums? It would be nice if someone from Apple could shed some more light on this error message or at least where more information can be obtained regarding what is actually causing the problem. I even tried replacing the directory utility app on a lion machine with one from a SL machine (desperate, I know), but to no avail. If some have it working, there must be something about certain AD configurations that Lion just does not agree with.


It seems pretty clear that Apple is turning their focus away from the medium business/enterprise market. First, they dropped blade servers, then they released the app store (an administrator's worst nightmare for controlling what is on their machines), then they lightened the server OS to be more "end user" friendly, then they got rid of disks for Lion (a $69 USB drive is not a good replacement to a disc), and now even error messages relating to enterprise software are too vague to even make troubleshooting possible.


I guess I am venting, but it seems a little ironic to me that as more and more Macs are introduced where I work (my company cannot be the only one getting more Macs), enterprise products/support continue to whittle away. If there is no real resolution to this, does anyone know if there is a good 3rd party solution that does not require major tweaking or replacement of AD (neither of these will fly here) and is reasonably priced?

Sep 7, 2011 5:19 PM in response to Matt James1

Same for me.


dsconfigad syntax has changed somewhat so i had to adjust that in the script... also the searchpath.


My script gives error 5202 initially, but if I reboot, and run it again, it works. Seems like scutil is to blame as I need some user input in order to rename my systems prior to binding them. But for whatever reason the new name is not in effect when dsconfigad is run in the script, and doesn't work until the system is rebooted.

Sep 22, 2011 9:23 PM in response to ragenkagen

Oh good! Its not just me....


I raised this issue months ago when the version changed to 10.6.x and was told by Apple Lion would fix it...

It didnt, it fact it made it work... the version of Snow Leopard on the mac mini worked perfectly!


I have had mixed results so far... Initially binding to my 2008 mixed mode domain only worked if we specificed a specific Domain Controller and that has worked with a number of machines, our initial fleet of 5 machines for instance


A few weeks ago my lion client was rebooted and on power up it ahd lost its domain binding and nothing would work to get it back on. Im now stuck using a mobile account version of my account...


My new Lion Server just arrived and im following the same procedure and it doesn't work either giving me fairly generic error messages like the one you initially mentioned that leave me confused... In the middle of this project we upraded to 2008 DCs but are still running in 2000 mode...


We are looking at swapping to mac hard ware for our client base and if this issue isnt resolved I cannot move forward; joining a domain is step 1 of a Windows Install usually...


Thanks


Andrew

Oct 5, 2011 2:58 PM in response to ragenkagen

I've found the source of this problem for me, and have been able to bind without further issue. Even though I'm connected to the internet, and using the Apple time server, the time on machines is not at all correct, which prevents the machines from binding to AD. I perform the below steps:


  1. Change the date and time to the correct values (or within the acceptable threshold of your AD).
  2. Restart the machine (will not work if you do not restart).


My machines are now happily binding to AD. 🙂


Josh

Cannot Join OS X Lion to Active Directory 2003

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.