Skip to main content
Question

Permissions for the JAMF LDAP Server Account

  • September 14, 2022
  • 4 replies
  • 11 views

Forum|alt.badge.img+5

Can anyone please clarify what permissions are required for the LDAP Server Account?

What functions does it perform aside from user/group lookup and authentication?

TIA

4 replies

sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • 3567 replies
  • September 14, 2022

@justin_gray It's just read-only lookup and auth


Forum|alt.badge.img+5
  • Author
  • New Contributor
  • 4 replies
  • September 15, 2022

What issue are you encountering?


Forum|alt.badge.img+5
  • Author
  • New Contributor
  • 4 replies
  • September 16, 2022

@justin_gray It's just read-only lookup and auth


If that's the case, do you know what account is used or what mechanism is responsible for AD joins? If I recall, there was a change with OS X where a regular user account could not join to the domain.


sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • 3567 replies
  • September 16, 2022

If that's the case, do you know what account is used or what mechanism is responsible for AD joins? If I recall, there was a change with OS X where a regular user account could not join to the domain.


@justin_gray The account you use for LDAP lookups should not be the same account you use for AD binding as the latter will definitely require different permissions. You should ask your AD team about that. You should also consider whether or not you actually need to bind your Macs to AD.