Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Mobile accounts not expiring

Hi everyone,


We have all of our Macs (running 10.7) bound to AD through the native plugin. We have the AD plugin set to create mobile accounts. We create three local groups on each machine and add the equivilent AD groups to the local groups. For instance, we have a local group called Students which has the member DOMAIN\AD Students. We then use local managed preferences to launch a login script to map drives for these accounts, which works correctly based on group membership.


We've now set these same three local groups to have mobile account expiration. On a test machine, we set it to 2 days. We then logged in with a test account and rebooted, logged in again, and rebooted. After waiting all week, the account is still there (along with all of the other mobile accounts, but we don't know exactly when those students had logged in).


Is there any place to check where the last time a user logged in? Does our setup sound like it should even work?


Thanks!


-MRCUR

Posted on Jan 24, 2013 5:33 AM

Reply
5 replies

Feb 19, 2013 5:07 AM in response to MRCUR

When logging in with an AD user, the "lastLoginTime" is not set on the mobile account. This seems to be the root cause of the accounts not expiring as expected, as the lastLoginTime is used to determine when the account should expire.


This unfortunately seems like expected behavior when using AD accounts as opposed to local or OD accounts.

Mobile accounts not expiring

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.