image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X Server

Reply
 
LinkBack Thread Tools
  #1  
Old April 9th, 2009, 11:59 AM
Registered User
 
Join Date: Oct 2008
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Matt OS X is on a distinguished road
Window 2003 server issue.

Hello all,

I googled for this issue but couldn't find any answers. I hope you guys can help me out here.

Here's a situation:

I am an apple technician for a university. All mac domains are registered under window server 2003 with Active Directory. One Department wants to have their 5 pcs computers and 1 mac have restrictions log in workstation with their department A.D. with one username that allows them to login these 6 computers in their department office only but not login to ANY other computers on campus.

The window server 2003 had successfully restricted one A.D username to 5 PCs but failed to recognize 1 mac even though I typed in its bind address. One username that CAN'T be logged in to ANY macs on domain EXCEPT for one particular mac. If using the local user restrictions on one mac, the username can STILL be logged in to OTHER domain macs. This is for security reasons to have the username to use ONE mac. Hope this clears up what I'm trying to say.

Thanks in advance!
Reply With Quote
  #2  
Old April 18th, 2009, 03:18 AM
Michael Dhaliwal, ACSA
 
Join Date: Mar 2003
Location: Chicago, IL
Posts: 1,071
Thanks: 0
Thanked 3 Times in 3 Posts
Go3iverson is on a distinguished road
I may be misunderstanding you (I admit I did get a bit lost in the explanation, possibly from lack of sleep), but it sounds like you want to enforce policy that restricts login to specific users to specific machines. You would need to supplement your Active Directory to do this, most commonly by adding an Open Directory domain and binding your Macs to both. The Open Directory would be able to enforce the machine level policy you are looking for (as it sounds).

Michael
__________________
Michael Dhaliwal
ACSA, Xsan Certified, etc, etc...
District13 Computing
Reply With Quote
  #3  
Old April 21st, 2009, 02:00 PM
Registered User
 
Join Date: Oct 2008
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Matt OS X is on a distinguished road
Quote:
Originally Posted by Go3iverson View Post
but it sounds like you want to enforce policy that restricts login to specific users to specific machines. You would need to supplement your Active Directory to do this, most commonly by adding an Open Directory domain and binding your Macs to both. The Open Directory would be able to enforce the machine level policy you are looking for (as it sounds)
Can you please help me out with this? Like explaining how to make this effectively. Thanks.
Reply With Quote
  #4  
Old October 27th, 2009, 11:54 AM
Registered User
 
Join Date: Apr 2005
Posts: 13
Thanks: 0
Thanked 0 Times in 0 Posts
anykey is on a distinguished road
I am no great expert, but I think that you need Apple Open Directory (i.e. have an xserve with OD enabled) integrated in with Active Directory to help you manage the Macs. Maybe?
Should be fairly easy to integrate these days if up to date OS X 10.5 or 10.6?
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump


All times are GMT -5. The time now is 04:10 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0 RC1
Copyright 2000-2010 DigitalCrowd, Inc.