Groups from Active Directory show 0 members

Hi,


I am trying to setup a new MacOS Server running on a Mac Mini with OS X 10.13.1 as part of the Golden Triangle for integrating Mac machines onto a windows domain network. I have installed MacOS Server and then afterwards bound the Mac server to our Active Directory. MacOS Server then populates with all the users and groups from AD however it does not populate the groups from AD and leaves them with 0 members.

When I look at the properties of an individual user from AD it shows them as a member of the groups that they should be but this is not reflected on the Groups pane for some reason?


I have tried unbinding and rebinding the server to Active Directory, completely rebuilding the server, leaving it running overnight, increasing the maximum LDAP request per page on AD. Nothing seems to be populating the groups from AD.


Any ideas?

Mac mini, macOS High Sierra (10.13.1)

Posted on Nov 21, 2017 1:23 AM

Reply
2 replies

Nov 22, 2017 2:51 AM in response to Antonio Rocco

Hi Antonio,


I had set up the DNS A record and rDNS on our server before installing the MacOS Server software and made sure that the Mac Mini's IP was static and the current IP is still the same on both the mac mini and the DNS record so I don't think that is an issue.

We are a single domain site.

We unfortunately do use .local in our domain and I am unable to change that at this time.

both the Server.App and Profile Manager show all the groups from Active Directory but they all show as having 0 members in them. E.G. the group 'All Staff' has every staff user in it when viewed on Windows Active Directory Users & Computers but shows no members when viewed on the Server.app or Profile Manager.


I did notice recently, and I am not sure what changed, that groups will show members if you right click on a group and go to Edit Group. The member list will populate after a few seconds but if you click ok it will ask for a username and password for that directory node. None of our AD administrator accounts work and neither does the Open Directory admin created with the mac server. The AD accounts bring up an error saying that the user is not an administrator on that directory node and the Open Directory admin will instead shake the popup as if the wrong password was entered. But it is not the wrong password because I am able to log in to the server using it.


Another thing I also found while testing some settings is that there is a primary group setting in Active Directory with the description "There is no need to change Primary group unless you have Macintosh clients or POSIX-compliant applications" I have set the primary group for a few staff accounts to 'All Staff' and a couple of accounts appeared in Profile Manager but others did not. I am not sure what is different between the accounts as all their properties settings are identical.

I have had a look at our groups in Directory Utility as you suggested and found that all our AD groups have users under the GroupMembership property. So I am able to see that users do appear in their groups but for some reason the MacOS Server software is not showing this. Could it be something to do with the authentication issue I mentioned above?


Thanks for taking the time to suggest a few things, I appreciate it.

Nov 22, 2017 2:51 AM in response to BrookfieldSch

As ever successful Open Directory as well as Active Directory Integration all rests on DNS. Getting this bit right is absolutely fundamental to how well it all works. General requirements are fixed IP addresses with appropriate A and rDNS records for all your servers including your mac server. It's also not a good idea to use .local as the tld for your domain. The use of internal proxies can also display odd behaviour on OS x server and client.


It's more than possible you've got all of this covered and I'm only asking as it is very important. Having said that and assuming you've started the service, what does PM show? Have you tried searching for Groups in the Server.App and/or PM? You can browse the AD node using dscl in terminal or the Directory Editor in Directory Utility. Directory Utility is in /System/Library/CoreServices/Applications. It's odd how you can see users but not groups? Is this a multiple domain AD or a single one? Another possibility for non-appearance of AD groups is it's a 'feature' in the Server.App and is apparent only in your particular environment? I have seen similar in other environments and it's very difficult to find out why this happens sometimes. Not particularly helpful I know but it may lead you elsewhere which may help you further?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Groups from Active Directory show 0 members

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.