Skip to main content
Question

Your experiences joining Macs to AD with a profile

  • February 17, 2015
  • 5 replies
  • 43 views

davidacland
Forum|alt.badge.img+18

Hi all,

I've traditionally used dsconfigad and/or Directory Utility to join Macs to AD. As you can now join the domain with a config profile, I wondered if there was anyone using this method and if you had any experiences (good or bad) to share?

5 replies

davidacland
Forum|alt.badge.img+18
  • Author
  • Valued Contributor
  • February 18, 2015

Ok, it doesn't look promising!

external image link


Forum|alt.badge.img+7
  • Contributor
  • February 18, 2015

Hey davidcland,

We originally did decide to use configuration profiles, but found there was an issue with AD binding through there (Which if i read correctly was fixed in 9.64). With configuration profiles, they enforce that the machine be bound the the specific AD you designate even if the user attempts to remove it.

We however decided to go with policies due to the AD configuration profile was not working properly for AD, but would keep switching to OD mode which caused some confusion at first. With policies, you do have some leverages you can use, such as placing the policy in self service for technician use.


Forum|alt.badge.img+18
  • Contributor
  • February 18, 2015

That sounds scary, I assume you need to embed plaintext credentials in the profile to bind?


Forum|alt.badge.img+7
  • Contributor
  • February 18, 2015

Once you have entered the password, they become blanked out with dots. So if someone happened to gain access your JSS, they would not gain access to your AD password.


davidacland
Forum|alt.badge.img+18
  • Author
  • Valued Contributor
  • February 18, 2015

Thanks for the feedback. Doesn't sound like it's quite ready yet!