Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Mac OS X Server File Shares and Active Directory Users

About ready to pull my hair out on this one...


We have a department that only uses Macs. At the moment, it's a hodgepodge of different setups. We were able to convince the department to standardize, and purchase a Mac Mini Server. To keep things a bit simpler, we are setting up their department shares on the server as well.


To make my life simpler (or so I thought...) I decided to bind the OS X Server to our AD, and use the AD users/groups to allow access to the shares. The OS X Server app lists all of our AD user and groups, and I can apply them to the shares, however, when we try to access the share, it fails.


I don't think the server is talking to our AD correctly.


I can login to the Mac Server with my network account, my network account works for accessing Server.app, but nothing I've tried will allow our Mac or Windows clients to access the shares with the AD credentials. The log file comes up with:


mccsrvrmac.mcc.local smbd[441]: check_account - [7]: [permission denied] pam_acct_mgmt


Also seeing this:


mccsrvrmac.mcc.local kdc[57]: Asked for LKDC, but there is none


A bit of background: We added this Mac to the domain once before, realized that the HDDs weren't setup in a RAID config, so wiped it and reinstalled. I did remove the computer account before rebinding.


Any help is appreciated!

Mac mini, OS X Server

Posted on Aug 29, 2012 8:29 AM

Reply
Question marked as Best reply

Posted on Aug 30, 2012 6:41 AM

I figured this out. In Mountain Lion Server, it doesn't matter if you give the user rights to a shared file or folder, if the user doesn't have access the File Sharing service, they can't get it. I had to find the specific users in the Server app under the AD in the Users tab, and give them rights to the File Sharing service. I think you can do this for a whole AD group as well, but I haven't tried.

6 replies
Question marked as Best reply

Aug 30, 2012 6:41 AM in response to MCCMIS

I figured this out. In Mountain Lion Server, it doesn't matter if you give the user rights to a shared file or folder, if the user doesn't have access the File Sharing service, they can't get it. I had to find the specific users in the Server app under the AD in the Users tab, and give them rights to the File Sharing service. I think you can do this for a whole AD group as well, but I haven't tried.

Mac OS X Server File Shares and Active Directory Users

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.