ADPassMon + Kerbminder = Success?

danshaw
Contributor II

Curious if anyone is using both of these apps in their environment and how its going. We currently have a bunch of Mac's in the field and they are authenticated mobile accounts bound to AD. Users have to log into the VPN to change their passwords.

ADPassMon is great, but we do have a few issues here and there with Kerberos tickets needing to be refreshed or re-created and its a manual process right now with our techs. Wondering if this combination would be as great as it looks.

Thanks guys!

3 REPLIES 3

etippett
Contributor II

I'm wondering the same...

warrengottlieb
New Contributor

The combo has been working well for us. ADPassmon itself was good, but we'd run into users being unable to change their passwords though it, after their tickets expired—and ADPasmon wouldn't give an error, just an unsuccessful password change. Kerbminder seems to have solved that for the most part—by refreshing the tickets in the background, we've drastically reduced the number of users who have to log out and back in to reset their passwords. It's also reduced the pause when authenticating in from the screensaver or login screen—no more timeouts when the computer only has expired tickets, defaulting to cached creds.

In our environment (the VPN is handing out the same DNS zones as we do on-net) we can also use ADPassmon to change passwords over the VPN, a real help for out-of-office users.

danshaw
Contributor II

Thanks @warrengottlieb! I think I will move forward on our implementation and give it a go.