Anyone using OS 10.8.2 and Active Directory, and successful login and account creation

johnklimeck
Contributor II

Is anyone having success with this, or is most everyone still using OS 10.7.5

Can successfully bind a clean 10.8.2 image with dsconfigad, mobile enable, to Windows AD 2008 R2, all is good there.

Can login with valid AD user, but OS X does not really finish the process. The Finder hangs (Finder icon bounces in the dock, no Apple menu bar, and question mark icons in the dock. The local account is never created, can login as admin and check with dcxl, no user, no home directory.

This does not happen in 10.8.0, or 10.7.5 (separate issue and topic thread for 10.7.5).

Total deal breaker for us. Have logged a bug with Apple and spoken to an Apple engineer. Can reproduce everytime, and this is not the OS X image. A brand new image downloaded directly from Apple (Recovery HD) on i7 MacBook Pro.

Thx,

John K

46 REPLIES 46

sgrall
New Contributor III

For those who haven't seen the article:

OS X Mountain Lion: Improving mobile user login times for Active Directory .local domains
http://support.apple.com/kb/HT5738

asid-russ
New Contributor

I had the same problem as well and found a solution. For me, I found out it would only happen to AD Users who had local administrator access to the Mac (In the AD Bind settings on the mac, there's a section for assigning AD Users to the local admins group). When I removed the AD User from the AD group that was assigned local admin privileges (and waited for AD replication), I was able to log in without the issue!

Not applicable

Between 10.8.4 and removing all Windows Server 2003 DCs, this has been resolved for my org as well.

TheMacGuy
New Contributor

I'm having this exact same problem johnklimeck described at the beginning with a brand new iMac running 10.8.4 joining an Active Directory 2008 domain. I've tried all of the suggestions listed in this thread with no success. My older iMacs running Snow Leopard that have been on the domain for 3 years are working fine. No account name conflicts between the local system and AD. Right now the system is being used to develop a template for an 18 station lab so all the work is being done by hand.

Any other suggestions on what to try?

I should add that for about the first 15 seconds after a restart, there is a notice at the login screen that "Network Accounts are Unavailable" but then it goes away and when I go Login Options>Directory Utility, everything looks good.

Howell
New Contributor

I'm having this exact same issue as originally posted.

AD 2008 R2 OS X 10.8.4

I can log in as most AD accounts. The account that I need to use is not logging in all the way. Question marks on the dock bouncing Finder on the dock. When I attempt to open Notes or Mail; I get an error that the Library needs to be repaired. Its not creating a Home Folder under /Users.

I have tried everything listed above. Does anyone else have any ideas.

Howell
New Contributor

I found a resolution to my issue if anyone stumbles across this.

First I had to disable the option to create a mobile account upon log in in Active Directory settings in OS X. This allowed me to get the user logged in but, the mobile account creation would fail.

Second follow these steps:
1. Delete the old user if that user exists on the client system.

  1. Test to make sure the system is properly bound to Active Directory.

  2. Login as the local admin and run the following command in the
    Terminal:
    sudo
    /System/Library/CoreServices/ManagedClient.app/Contents/Resources/createmobileac count
    -n userid -v

Remember this will require a password and will not return any visual
output when the keys are pressed.

  1. Log out the local admin.

  2. Log in as the Network user.

  3. To configure the syncing service go to System Preferences >
    Accounts and click on the Settings button. This will be grayed out
    with users who are not set up with a network home directory.

Hope this helps.

croehl
New Contributor

Follow these steps pay special attention to 7-10, that is what tripped me up.

  1. Open System Preferences and click Accounts.

  2. If the lock icon is locked, unlock it by clicking it and entering the name and password of an administrator.

  3. Click Login Options, then click Join or Edit.

  4. Click Open Directory Utility.

  5. If the lock icon is locked, unlock it by clicking it and entering the name and password of an administrator.

  6. Click Services.

  7. In the list of services, select Active Directory and click the Edit (/) button.

  8. If the advanced options are hidden, click Show Advanced Options.

  9. Click User Experience, then click “Create mobile account at login,” and optionally click “Require confirmation before creating a mobile account.”

  10. If both options are selected, each user decides whether to create a mobile account during login. When a user logs in to Mac OS X using an Active Directory user account, or when logging in as a network user, the user sees a dialog with controls for creating a mobile account immediately.

  11. If the first option is selected and the second option is unselected, mobile accounts are created when users log in.

  12. If the first option is not selected, the second option is disabled.

  13. Click OK.