Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

how do i manage my mac clients with active directory on a lion osx server?

so i have the following:


Lion server running 10.7.2

Windows Server 2008r2 (managing DNS, DHCP, AD...)


i want to be able to use my Active Directory username/passwords for authentication on client computers. i also want to be able to restrict some features like Users & Groups and be able to host printers on this server.


how do i go about doing that?

Mac Pro, Mac OS X (10.7.2), Server

Posted on Dec 2, 2011 2:50 PM

Reply
Question marked as Best reply

Posted on Dec 3, 2011 5:42 PM

Bind your Mac systems to AD. That simple act will likely give you 90% of what you are looking for. You do this through System Preferences > Accounts > Login Options (or alternately throught Directory Utility or dsconfigad).


Now this will give you authentication and authorization from the AD domain plus group memberships and single sign on to Kerberos services (file services, Exchange, etc). Binding to AD will not allow you to do group policy. If you are looking to do managed client, then you have a number of options.


They include AD Schema Mod (only do this if you absolutely must), 3rd party tools like Centrify (as they give you Windows tools to manage Macs), or OS X Server and the use of the "magic triangle."


The triangle is the binding of Mac workstations to both AD and OS X Server. All authentication and authorization comes from AD and then management comes from OD using native Apple tools. This way you don't annoy anyone in the AD team by asking them to modify the environment.


This is a wise choice to bind the systems. If makes Macs first class citizens (well, almost).

23 replies

Oct 8, 2012 3:40 AM in response to Beandip408

So I have read, but we have three large sites and our Network Manager refuses to change it. I have to say, that I have not noticed any problems during the past 3 years we have been integrating macs. We use the golden triangle method with SL servers.

I am now looking into ML and profile manager so I hope this .local issue doesn't rear its head.

how do i manage my mac clients with active directory on a lion osx server?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.