Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Time for changed access to shares to take effect?

Recently put in a Yosemite mac mini "server" to replace 2 working but aging 2007 Xserves for file sharing.We're using Active Directory for authentication.


Due to our environment, we frequently need to change group access to users to mange conflicts. For example employee A working on Brand X one week, next week she needs to work on Brand Y, but Brand X and Brand Y are conflicts so she can only have one or the other. Anyway, when I change group access in Active Directory, sometimes it takes quite a long time, half an hour, an hour, or more, for the access to take effect (for the share point to show up when the user connects from the Finder).


Is there any way to manually "sync" this process with a command line command or something? Or a setting somewhere that says how often the Yosemite server refreshes from Active Directory? By the way this problem was there with our 10.6 Xserves, I was just hoping it would be improved with Yosemite.

Speaking of this, a major disadvantage from an admin perspective is the "Allow Admin to masquerade as a user" feature seems to be gone in Yosemite- that was really useful in attempting a logon as a user and seeing if their new share access had taken effect 🙂

Mac mini, OS X Yosemite (10.10.2)

Posted on Feb 5, 2015 6:43 AM

Reply
2 replies

Mar 2, 2015 10:54 AM in response to theFerret

It doesn't refresh even if the user disconnects (or if i test it with a user that is not already connected).


I think I found a workaround, though. If I change the preferred domain controller from Terminal with


dsconfigad -preferred domaincontrollername


It seems to refresh and the new authorizations take effect. But if I add groups to another user even seconds later, i need to run the command again to have it refresh again.


Hopefully this helps someone else. I'm wondering if there is any downside to scripting it to run every 15 minutes or so to guarantee a refresh (we're expecting to allow some non technical users to modify AD users and groups and I'd hate to have them issuing commands on the server as well).

Time for changed access to shares to take effect?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.