<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VMtoday &#187; domain</title>
	<atom:link href="http://vmtoday.com/tag/domain/feed/" rel="self" type="application/rss+xml" />
	<link>http://vmtoday.com</link>
	<description>VMware News, Views, &#38; How-To&#039;s from Josh Townsend</description>
	<lastBuildDate>Thu, 02 Sep 2010 05:11:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>OT: Joining a Mac to a Windows Active Directory</title>
		<link>http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=ot-joining-a-mac-to-a-windows-active-directory</link>
		<comments>http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 21:24:27 +0000</pubDate>
		<dc:creator>Joshua Townsend</dc:creator>
				<category><![CDATA[General IT]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[fusion]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://vmtoday.com/?p=129</guid>
		<description><![CDATA[We picked up a few new 17&#8243; MacBook Pro&#8217;s at work. We&#8217;re a Microsoft shop, so Mac&#8217;s aren&#8217;t part of the basic knowledge for our IT staff, myself included. I don&#8217;t want to be the Windows guy who says &#8220;I don&#8217;t do Macs&#8221; &#8211; part of being a technologist is serving the user base where [...]


Related posts:<ol><li><a href='http://vmtoday.com/2009/11/vsphere-upgrade-breaks-active-directory/' rel='bookmark' title='Permanent Link: vSphere Upgrade Breaks Active Directory'>vSphere Upgrade Breaks Active Directory</a> <small>I recently completed a VMware VI 3.5 to vSphere upgrade...</small></li>
<li><a href='http://vmtoday.com/2009/01/vi-toolkit-for-windows-v15-released-today/' rel='bookmark' title='Permanent Link: VI Toolkit for Windows v1.5 Released Today'>VI Toolkit for Windows v1.5 Released Today</a> <small>VMware released version 1.5 of the VI Toolkit for Windows...</small></li>
<li><a href='http://vmtoday.com/2009/12/windows-2008-r2-svga-drivers/' rel='bookmark' title='Permanent Link: Windows Server 2008 R2 &#038; Windows 7 Freeze When Using SVGA Drivers'>Windows Server 2008 R2 &#038; Windows 7 Freeze When Using SVGA Drivers</a> <small>I recently ran into an issue when installing my first...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>We picked up a few new 17&#8243; MacBook Pro&#8217;s at work.  We&#8217;re a Microsoft shop, so Mac&#8217;s aren&#8217;t part of the basic knowledge for our IT staff, myself included.  I don&#8217;t want to be the Windows guy who says &#8220;I don&#8217;t do Macs&#8221; &#8211; part of being a technologist is serving the user base where they are at with the technologies they require to do their job (but please, included me in determining your requirements and technological solutions &#8211; a Mac might be really cool, but might not fit with the organizations needs or your IT group&#8217;s ability to support your solution).  Really, that&#8217;s what Web 2.0 is all about &#8211; compatible, interchangeable tools that offer customized functionality for the users&#8217; abilities and needs.  Come to think of it, that&#8217;s what VMware is all about too &#8211; the right resources in the right place at the right time, independent of underlying hardware, application/OS agnostic, able to rise above local shortcomings by pushing to the cloud&#8230;.</p>
<p>To be fair, I was issued a Mac at a previous company, but didn&#8217;t care much for it as the programs I had to run for my job were Windows based.  I ran VMware Fusion, but it could only take me so far &#8211; funny things start to happen when you are in a VM, RDC&#8217;ing to a client server, opening the VI client and console&#8217;ing to a VM.  Shortcut keys behave strangely, and one can only create so many alternate key mappings before going insane.  It wasn&#8217;t the right tool for me and my job, but Macs do serve some purposes very well &#8211; graphic design and iPhone app development in my current case.</p>
<p>I didn&#8217;t have a requirement to do much customization the new Mac&#8217;s, but they did have to allow users to authenticate to the current Microsoft Windows Active Directory Domain.  I hit a few snags as I went through the process, including making domain users local administrators and allowing domain users to log in to the Mac while off-line.  Here is what I came up with for a final process in my environment &#8211; adjust according to your needs:</p>
<p>1.) Configure OS X to talk to the Active Directory</p>
<ul>
<li> Using Spotlight (LeftCommand+Space), open the &#8216;Directory Utility&#8217;</li>
<li> Switch to the Services tab</li>
<li> Tick the box next to Active Directory plug-in (Note: You may have to click the lock icon to make configuration changes).</li>
<li> Highlight the Active Directory plug-in and click the Configure icon (pencil icon).</li>
<li>Enter an Active Directory Domain, using the FQDN (example: mydomain.local)</li>
<li>Enter a Computer ID.  This ID will be used to create a computer object in the AD.</li>
<li>Expand Advanced Options:
<ul>
<li>On the User Experience Tab:
<ul>
<li>Check the box for &#8216;Create mobile account at login&#8217;.</li>
<li>Uncheck the box for &#8216;Require confirmation before creating a mobile account&#8217;.</li>
<li>Choose the &#8216;Use UNC path from Active Directory to derive network home location&#8217; if your AD is set to map a user&#8217;s home location to a UNC and/or DFS path; if not, you may want to uncheck this option.</li>
</ul>
</li>
<li>On the Administrative tab:
<ul>
<li>Check the box for &#8216;Allow Administration By:&#8221; and then Add the Active Directory &#8216;domain admins&#8217; and &#8216;enterprise admins&#8217; group</li>
<li>Check the box for &#8216;Allow Authentication from any domain in the forest&#8217; if appropriate for your environment</li>
</ul>
</li>
</ul>
</li>
<li>Click the Bind button and enter credentials for an account with permissions to join the domain on the Active Directory domain you are joining.  Note: The computer account may appear in the default AD &#8216;Computers&#8217; container even if the redircmp utility was used on the domain to change the default Organizational Unit (OU) of new computers joining the domain.</li>
<li>Click OK.</li>
<li>Verify that the Active Directory Domain that you configured correctly appears with a green dot on the &#8216;Directory Servers&#8217; tab of the Directory Utility.</li>
<li>Close the Directory Utility.</li>
</ul>
<p>2.) Configure basic login options</p>
<ul>
<li>Open the Accounts tool from Apple | System Preferences | Accounts</li>
<li>Click Login Options (Note: you may have to click the lock icon to allow changes to be made).</li>
<li>Configure the Login Options settings as follows:
<ul>
<li>Automatic Login: Disabled</li>
<li>Display login windows as: Name and Password</li>
<li>Check the box for Allow network users to login to this computer.
<ul>
<li>Click the Options button and configure all network users (i.e. &#8211; all Domain users) or only select users to have login permissions.</li>
</ul>
</li>
<li>Configure other options as desired.</li>
</ul>
</li>
<li>Log out of the local Admin account</li>
</ul>
<p>3.) Log in using a domain user account (with permissions to login to the server (see above) while connected to the network) using the AD user.name and password</p>
<ul>
<li>The first login may take several minutes to complete as a local account is being created.</li>
<li>Open the Accounts tool from Apple | System Preferences | Accounts</li>
<li>Highlight the logged-in user&#8217;s account.
<ul>
<li>Check the box for &#8216;Allow user to administer this computer&#8217; as appropriate</li>
</ul>
<ul>
<li>Verify that the &#8216;Settings&#8217; button for Mobile Account is grayed out &#8211; this means that an offline account has been created for the user.</li>
</ul>
</li>
</ul>
<p>4.) Test the config by removing network connectivity (disable AirPort and/or pull the network cable) and log in as the user you just configured.</p>
<p>5.) Buy <a href="http://vmware.com/products/fusion/" target="_blank">VMware Fusion</a> so you can run Windows on your Mac when all the stuff you were used to just ain&#8217;t there anymore   <img src='http://vmtoday.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':-D' class='wp-smiley' /> </p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center">
<ul class="socials">
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=OT%3A+Joining+a+Mac+to+a+Windows+Active+Directory+-+http://bit.ly/amWj5r&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/&amp;title=OT%3A+Joining+a+Mac+to+a+Windows+Active+Directory" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/&amp;title=OT%3A+Joining+a+Mac+to+a+Windows+Active+Directory" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/&amp;title=OT%3A+Joining+a+Mac+to+a+Windows+Active+Directory" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22OT%3A%20Joining%20a%20Mac%20to%20a%20Windows%20Active%20Directory%22&amp;body=Link: http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A We%20picked%20up%20a%20few%20new%2017%22%20MacBook%20Pro%27s%20at%20work.%20%20We%27re%20a%20Microsoft%20shop%2C%20so%20Mac%27s%20aren%27t%20part%20of%20the%20basic%20knowledge%20for%20our%20IT%20staff%2C%20myself%20included.%20%20I%20don%27t%20want%20to%20be%20the%20Windows%20guy%20who%20says%20%22I%20don%27t%20do%20Macs%22%20-%20part%20of%20being%20a%20technologist%20is%20serving%20the%20user%20base%20where%20they%20are%20at%20with%20the%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-printfriendly">
			<a href="http://www.printfriendly.com/print?url=http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/" rel="nofollow" class="external" title="Send this page to Print Friendly">Send this page to Print Friendly</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/&amp;title=OT%3A+Joining+a+Mac+to+a+Windows+Active+Directory" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/&amp;title=OT%3A+Joining+a+Mac+to+a+Windows+Active+Directory&amp;srcUrl=http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/&amp;srcTitle=OT%3A+Joining+a+Mac+to+a+Windows+Active+Directory&amp;snippet=We%20picked%20up%20a%20few%20new%2017%22%20MacBook%20Pro%27s%20at%20work.%20%20We%27re%20a%20Microsoft%20shop%2C%20so%20Mac%27s%20aren%27t%20part%20of%20the%20basic%20knowledge%20for%20our%20IT%20staff%2C%20myself%20included.%20%20I%20don%27t%20want%20to%20be%20the%20Windows%20guy%20who%20says%20%22I%20don%27t%20do%20Macs%22%20-%20part%20of%20being%20a%20technologist%20is%20serving%20the%20user%20base%20where%20they%20are%20at%20with%20the%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>



<p>Related posts:<ol><li><a href='http://vmtoday.com/2009/11/vsphere-upgrade-breaks-active-directory/' rel='bookmark' title='Permanent Link: vSphere Upgrade Breaks Active Directory'>vSphere Upgrade Breaks Active Directory</a> <small>I recently completed a VMware VI 3.5 to vSphere upgrade...</small></li>
<li><a href='http://vmtoday.com/2009/01/vi-toolkit-for-windows-v15-released-today/' rel='bookmark' title='Permanent Link: VI Toolkit for Windows v1.5 Released Today'>VI Toolkit for Windows v1.5 Released Today</a> <small>VMware released version 1.5 of the VI Toolkit for Windows...</small></li>
<li><a href='http://vmtoday.com/2009/12/windows-2008-r2-svga-drivers/' rel='bookmark' title='Permanent Link: Windows Server 2008 R2 &#038; Windows 7 Freeze When Using SVGA Drivers'>Windows Server 2008 R2 &#038; Windows 7 Freeze When Using SVGA Drivers</a> <small>I recently ran into an issue when installing my first...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://vmtoday.com/2009/06/ot-joining-a-mac-to-a-windows-active-directory/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
