Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

How do I authorize OpenDirectory accounts to use ShareScreen?

A previous network administrator had set the old Mac Servers so that they can be administrated using ShareScreen. Any user marked as an administrator in OpenDirectory was able to log into the ShareScreen feature of the Mac Servers.


I have upgraded the systems, and now our network is running Mac OS X 10.9 with Server 3.0.2, but I am not able to log into these servers without using one of the local accounts on each machine. How does one change the settings of each of the Maverick's machines so that I can allow network users to log in without giving them a list of the local administrator account names and local administrator passwords for every machine that they need to log into?

Mac mini, OS X Mavericks (10.9.2)

Posted on May 28, 2014 10:43 AM

Reply
Question marked as Best reply

Posted on May 28, 2014 7:43 PM

You need to enable directory-based authentication on the ARD client. Then you need to create special groups (ard_manage, ard_interact, ard_reports, and ard_admin) in your Open Directory. Apple has a guide here http://images.apple.com/ca/fr/remotedesktop/pdf/ARD3_AdminGuide.pdf Start on page 60.


A quick one liner to enable directory-based auth is:


sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/k ickstart -configure -clientopts -setdirlogins -dirlogins yes


Read the documentation and avoid the section on using MCX.


R-

Apple Consultants Network

Apple Professional Services

Author "Mavericks Server – Foundation Services" :: Exclusively available in Apple's iBooks Store

2 replies
Question marked as Best reply

May 28, 2014 7:43 PM in response to Jared Clemence

You need to enable directory-based authentication on the ARD client. Then you need to create special groups (ard_manage, ard_interact, ard_reports, and ard_admin) in your Open Directory. Apple has a guide here http://images.apple.com/ca/fr/remotedesktop/pdf/ARD3_AdminGuide.pdf Start on page 60.


A quick one liner to enable directory-based auth is:


sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/k ickstart -configure -clientopts -setdirlogins -dirlogins yes


Read the documentation and avoid the section on using MCX.


R-

Apple Consultants Network

Apple Professional Services

Author "Mavericks Server – Foundation Services" :: Exclusively available in Apple's iBooks Store

How do I authorize OpenDirectory accounts to use ShareScreen?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.