Hello all!
I am new to JAMF and Casper, and I'd like a little more information on the following: After integrating LDAP and connecting Casper to Active Directory, how are password changes handled? We are a mixed PC and Mac environment, with Macs being bound to AD.
Currently any time a Mac user wants to change their network password, they must be hardwired. The same is true whenever a new user wants to log into a Mac for the first time, the Mac will not authenticate unless hardwired.
This causes a lot of issues, especially when a user has a Mac and a PC. I have consulted the Casper manual, but do not fully comprehend what I am reading, this is all very new to me.
We (the IT department that I am apart of) were looking to implement Open Directory and create a "magic triangle" but Casper support informed me that all of the above can be managed via Casper.
This (unanswered) thread is most like my problem: https://jamfnation.jamfsoftware.com/discussion.html?id=304
This thread indicates that we do not need Open Directory: https://jamfnation.jamfsoftware.com/discussion.html?id=12824
Below is part of my chat with Support:
Jay: Hi, my name is Jay with JAMF Software. How may I be of assistance?
Me: Hey Jay, how are you today?
Jay: Other than -25 windchill? Just peachy! :)
Jay: How are you doing?
Me: That sounds absolutely terrible!
Jay: It has gotta get better!
Me: I am well, a little confused! Perhaps you could help.
Jay: Happy to
Me: Appreciated.
Me: We have a mixed PC/Mac environment, and are currently only using Active Directory to manage these machines.
Jay: Like it so far..
Me: We are in process of migrating from Miraki MDM to Casper, and I was curious if Casper allowed for remote user management if the Apple machines are bound to AD? For example, End User passwords expire and must be changed every 120 days. Currently, a Mac user MUST be hardwired in order to change their password, otherwise the change does not propagate to AD, causing a password mismatch. We were looking to use a "golden triangle" using OD and AD, is this the wrong way of thinking?
Jay: All these rules can be set in Casper Suite. You may adhere to your Active Directory rules or establish new password policies via Casper. WIRELESSLY!
Any assistance will be greatly appreciated.
Thanks!