Skip to main content
Question

. Lets assume that all entered data is correct, but you receive a ‚Unable to bind to AD’ error. You tried pinging the AD server and it responded. What is the next basic thing to check?

  • March 8, 2018
  • 5 replies
  • 16 views

Forum|alt.badge.img+1

try to solve this

5 replies

mvu
Forum|alt.badge.img+20
  • Jamf Heroes
  • March 8, 2018

• Check time server on client is within 5 minutes of correct time
• Change the computer name or add a character to the end, then bind
• Go to System Preferences, Login Options. Make sure Allow Network users to log in window is checked off. Click "Options" and see if All Network users helps


Forum|alt.badge.img+5
  • Contributor
  • March 9, 2018

Delete the computer object in AD or rename the computer and try using a IP address for a DC instead of the FQDN. If the IP trick works then make sure DNS is setup correctly in your environment. Confirm you have a DNS PTR setup for all DC's in the environment.


talkingmoose
Forum|alt.badge.img+36
  • Community Manager
  • March 10, 2018

Verify the AD account you're using to bind has privileges to create objects in the OU you've specified in your binding. By default, it's something like: CN=Computers,DC=domain,DC=com, but that's different for every organization.

Be sure to test manually binding using the Directory Utility app in /System/Library/CoreServices/Applications. If you can bind with this app, the same information should work with Jamf Pro.


Forum|alt.badge.img+16
  • Valued Contributor
  • March 10, 2018

If it is a previously bound machine check the AD object is not disabled or moved to a stale container.


Forum|alt.badge.img+5
  • Contributor
  • March 12, 2018

check the DNS for lookup and reverse lookup.