Mobile Account Sync/AD Home Folder Question

I am in the process of building and testing a mac image for my end users. This is primarily a Microsoft Environment and Macs are NOT a certified platform (which I hope to change soon). All of my work for the end users in my department has been done on Macs for over 25 years and they've all logged on to these Macs using local admin accounts, connecting to all of their internal and external resources manually.


I have a Mac mini server running 10.11.6 and Server app 5.2. This is primarily a file server with project shares available for the users. I've recently enabled Open Directory and Profile Manager in order to create profiles for binding the Macs to AD, creating network shares that mount at login, proxy configuration and certificate trust chains. I am loading these profiles manually at the moment because the only MDM solution in-house is for corporate iDevice use only.


The current PC environment is Single Sign-On using network credentials. Upon installing the profiles, everything works when logging on with these credentials except the ability to cache credentials for remote work and sync home folder. When I login without cache or sync set on the network, the network home folder for the user is in the dock and accessible as if they were logged on to a PC...but off network, cannot login. This is what the User Experience tab shows in the utility:


User uploaded file

I've attempted to set Create mobile account on login (with and without Require confirmation checked) and I cannot uncheck Force local home directory on startup. I've also tried same scenarios with and without Use UNC path from AD checked. I can logon in all scenarios, but the network home location is either not available with a question mark on the dock folder or its available for about 1-3 minutes or until I attempt to open one of the folders...then it goes question mark and I have to manually connect to the share and move that to dock. But still no sync either way. Which is odd since we have read/write access according to AD permissions but syncing attempts give me the write permissions error at setup.


I read somewhere this week that something in a users AD profile (in the Profile tab, shown below) under home folder causes conflict if the share path uses the FQDN. For instance, if I go into the users advanced options in SysPrefs>Users&Groups, the Home directory always says /Users/[UserID]. In the AD profile (below), the drive letter used in our login script for drive mapping is set and the network path is shown for each user. if I access that manually, I can read and write to it no problem. if I set that as home directory, reboot and login, i can see the folder in the dock, i can expand it and even open the folders and move files around. but the moment i attempt to sync, write error.


User uploaded file

Given the path in the image above is a windows-based path and not smb or cifs, is that whats causing the issue? should I have our network server admins attempt to change our home folder to a path that a mac can use?


I should also point out that we use DFS for PC users to sync the selected folders. Perhaps that ties this all together...but as of now, I'm at a loss. If this is hard to understand, please feel free to ask and I will answer as best I can.


Thank you in advance for any assistance provided.

MacBook Pro (Retina, 15-inch, Mid 2015), OS X El Capitan (10.11.6)

Posted on Jan 13, 2017 9:58 AM

Reply

There are no replies.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Mobile Account Sync/AD Home Folder Question

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.