What if you actually want to use the iCoud Key-chain in your AD environment? Let me give you the cliff notes on our set up. (Keep in mind I inherited this system I am the new help desk manager)
- 500 plus Mac users. (we enable root and admin account, then add users. They are ALL local admins. Yeah I know bad idea.)
- Bound to AD.
- First.Last and AD password is required to log into their mac.
-Password set to NEVER expire. (yeah I know bad)
- 120 iPads and growing.
-Windows Servers. (we still have a bunch of PC's)
- Staff Wi-Fi is accessed by the users AD credentials.
-If someone has to have their Mac repaired or serviced they simply write their user name and password down and hand it to my staff! (Yeah I know even MORE of a bad idea.)
With that said I have my orders.... NO CHANGES to the Password system unless I can make it easy and SIMPLE!
Here is what I would like to have happen.
1. If the user goes to System Preffs and changes their user password I want it to change the keychain password, as well as their staff wifi, as well as their outlook for mac, or mail app.
2. I also want it to do this on their IOS devices.
I have been trying several different variations of settings described https://jamfnation.jamfsoftware.com/discussion.html?id=7783
and I am not having any luck. I still get asked for the original keychain password.
Apple says http://support.apple.com/kb/ht1631 that it should. But clearly I am missing something or what I am asking is just not possible. Either way I have only been in this position for a few weeks and this is something I want to change last week if not sooner!
Thanks in advance for your help!