Modify Active Directory users and groups from macOS Server
I've been trying to set up Server to handle the info from Active Directory a million ways but I can't seem to make it work. Whenever I edit anything, or not even edit, but open a user's properties page and click OK instead of Cancel it'll ask me for the domain admin password which I know, I am it, but it won't accept it.
If I type it correctly it will tell me the user is not an administrator on that node. If I type in something random in the box it'll just shake it off as wrong.
I like to make small edits to users without have to me going back and forth to a domain controller. Is this even possible or am I just wasting my time? It must be, otherwise I shouldn't even have options for editing properties of items hosted on other server, right?
I though about trying setting a copy of the AD userbase to Open Directory but at password changing time it'd be a nightmare changing two passwords, my users complain a lot as it is already.
If you could shed some light into this I'd be forever grateful, I've been searching nonstop about this for almost a month now but eveyone talks about the big picture, the end result, but skips management. Even the Apple white papers.
Thanks again.
I'm on Sierra, BTW. AD is on Windows Server 2012 R2, funny thing, I don't have any Windows computers other than the server farm but OS X/macOS OD has proven to be unreliable as a directory service.