Skip to main content
Question

About Enterprise Connect


Show first post

243 replies

Forum|alt.badge.img+7
  • Contributor
  • 28 replies
  • November 28, 2015

So itupshot:
This might not have all the answers but sure helped me a lot http://www.jamfsoftware.com/resources/getting-users-to-do-your-job-without-them-knowing-it/


Forum|alt.badge.img+9
  • Valued Contributor
  • 173 replies
  • November 28, 2015

@geoffreykobrien I'd be interested in taking a look at your script as well.

I have looked into ADPassMon, but I'm still not sure it'll help us get rid of the "Local Items" keychain issue.

@KDE82 Thanks for the link. That was a great presentation. I'm going to see if the GitHub for it is still online.


bentoms
Forum|alt.badge.img+35
  • Legendary Contributor
  • 4331 replies
  • November 28, 2015

@itupshot if a user forgets their old keychain password.

ADPassMon will reset their login.keychain & delete their local items & then restart their Mac.

There is some more work to be done, via adding some features from keychainminder


Forum|alt.badge.img+9
  • Contributor
  • 48 replies
  • November 30, 2015

Is EC available to US customers that have a worldwide presence? Are there any restrictions on its use outside the US?

What about use with multiple AD forests/domains? Is that handled when professional services configures it?


Forum|alt.badge.img+16
  • Legendary Contributor
  • 7880 replies
  • November 30, 2015

Based on the first post on this thread, one of the last sentences:

Enterprise Connect is only available to USA based customers

Emphasis is mine.

I think some of the Apple folks would need to confirm, but I read that as limited to companies that have their main headquarters in the US, not necessarily that it can only be installed in US locations. At least I would hope that's the only limitation, since many companies that could use this would be in the same situation; US based, but have offices in many locales around the world. It probably has to do with the on site professional services visit to get it set up.


Forum|alt.badge.img+14
  • Honored Contributor
  • 862 replies
  • November 30, 2015

For a non-bound Mac with a local account, does EC allow a user to print to a Windows print server without authenticating? I'm trying to figure out how to get away from IP based printing.

Also, for those posting to get updates on the thread - you can instead add a bookmark by clicking the plus sign at the top right and you'll get all email updates. :)

chris


Forum|alt.badge.img+6
  • New Contributor
  • 61 replies
  • December 3, 2015

I will also be very interested in EC once it's available to higher ed.


Forum|alt.badge.img+8
  • Contributor
  • 56 replies
  • February 23, 2016

Does anyone have any updates on Enterprise Connect? Has anyone purchased and implemented it? What are your opinions?


Forum|alt.badge.img+8
  • Contributor
  • 46 replies
  • February 24, 2016

Hi Matthew,

I purchased it and implemented it.

The “purchase” was more a 2 days contract for Apple Professional Services. The actual setup lasted an hour. APS engineers are very knowledgeable and super nice. Enterprise Connect doesn’t modify your infrastructure.

If you have a 'standard' AD setup, EC should integrate very easily. Otherwise, the 2 days might come in handy :)
If you want to test before, download and install KerbMinder. If it works straight away, chances EC will work too.

To be honest, in my case, EC wasn't better than KerbMinder, and I lost the possibility to tweak it myself. But the EC team is great and you get great Apple support.


Forum|alt.badge.img+8
  • Contributor
  • 56 replies
  • February 24, 2016

Hi ftiff,

Have you tested how well it works for unbound machines?

How do your users like it?

Are there any features that you know Apple wants to add to the product?


Forum|alt.badge.img+8
  • Contributor
  • 46 replies
  • February 24, 2016

Hey @mlavine

Yes, we use it exclusively on unbound machines.
Our users barely notice it. To be honest, they don't care. They have single sign-on, that all they want to know. Yes, I have quite a few features I'd like to add:
- remove the GUI, it's not needed and users don't like to have lots of icons in the menubar. It feels like windows
- push username and realm from a profile
- use AD login and password from the one entered in SetupAssistant. I hope this will come if it ever become native to OS X
- open a per-app VPN to get the kerberos ticket when outside of corporate network

But again, it works great.


Forum|alt.badge.img+4
  • Contributor
  • 19 replies
  • March 1, 2016

I work in government. Would this work with PIV/CAC enabled accounts? Can this support PIV/CAC logins to network shares, etc. How would that work with remote users? I can use via VPN.

This part is directly at Apple person that posted this. Please bring back PIV/CAC support in the OS natively. When it was dropped Macs in government were not that much. Nowadays, Macs are infiltrating at an exponential rate. Eliminate the 100% need for me to bind the Mac to AD and there will a whole lot more real fast. Yes, I have put feedback in on Apple page. I am just trying to get this heard wherever I can.


Forum|alt.badge.img+1
  • New Contributor
  • 2 replies
  • April 12, 2016

Does this tool work only with AD domains or does it also work with OD ?


Forum|alt.badge.img+5
  • Contributor
  • 33 replies
  • April 19, 2016

Why not just use Centrify? We use it as we purchased it prior to Apple releasing this but you can manage it all through GPO's, SSO, etc. Havent looked at pricing between the two but almost everyone from a security perspective knows Centrify.

https://www.centrify.com/

https://www.centrify.com/products/identity-service/mac-management/


Chris_Hafner
Forum|alt.badge.img+23
  • Jamf Heroes
  • 1716 replies
  • April 19, 2016

So far as I remember there is a significant price difference, but I don't have all those numbers off hand!


Forum|alt.badge.img+16
  • Valued Contributor
  • 401 replies
  • April 19, 2016

-ignore-


bradtchapman
Forum|alt.badge.img+20
  • Valued Contributor
  • 588 replies
  • May 12, 2016

@rkovelman Centrify is about $90/seat IIRC. How much does the Apple Enterprise Connect cost after the $5K integration? Maybe the cost of EC would make the difference for certain organizations.


easyedc
Forum|alt.badge.img+16
  • Esteemed Contributor
  • 623 replies
  • May 12, 2016

@bradtchapman Enterprise Connect is just the one-time professional services fee to configure it. It's also supported by Apple Care OS Support, so that's a plus too.


Forum|alt.badge.img+8
  • Contributor
  • 56 replies
  • May 12, 2016

@bradtchapman As far as I know you only pay once for Enterprise Connect and that is the initial $5500.


Forum|alt.badge.img+5
  • Contributor
  • 33 replies
  • May 12, 2016

You get what you pay for. I haven't seen it but FWIW people have given it bad reviews online. Still too new and missing too many functions.


easyedc
Forum|alt.badge.img+16
  • Esteemed Contributor
  • 623 replies
  • May 13, 2016

From the standpoint of EC is really 2 days of professional services with Apple and an App that would probably help in your environment, the cost is pretty low, IMHO. What functions are you looking for??


Forum|alt.badge.img+16
  • Legendary Contributor
  • 7880 replies
  • May 13, 2016

@rkovelman bad reviews online? Where exactly are these reviews you're referring to? Given this isn't something sold on the MAS or other public channels, I'd love to see such "reviews". Especially since as you say, you "haven't seen it" Or is this the old "I read it somewhere on the internet so it must be true" meme?


Forum|alt.badge.img+21
  • Contributor
  • 279 replies
  • May 13, 2016

We have purchased EC and had Apple add the ability to sync the AD password with the local password as this was the real issue keeping us from using the product. We are still in the development phase but we plan to reengineer our whole password policy and account enforcement around this app. It doesn't do everything but it is simple, lightweight, inexpensive, and being actively developed.


Forum|alt.badge.img+9
  • Valued Contributor
  • 187 replies
  • May 13, 2016

What i'd really like to see a Keychain remediation feature built-in to it, like ADPassmon...


Forum|alt.badge.img+21
  • Contributor
  • 279 replies
  • May 13, 2016

That would be nice, for sure. Until then it can fire off a script when a password change is made and you could do that now for the keychain items you want. They have an example script posted. We are using that script to post the new creds to our password sync took website.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings