It looks like you have to configure an OU to create an AD directory bind in Casper, but I know that with dsconfigad you can simply bind to a pre-existing object in AD without specifying an OU.
We're about to spin off a new company/domain taking thousands of our Macs, and rather than build a binding for each of our ~100 OUs (or script it via dsconfigad, which would expose AD credentials in the JSS in plantext if I have to pass a variable), I'd like to simply rejoin to the computer objects that we're cloning over to the new domain.
Has anyone had experience with this? Am I missing an easier way?
Edit: I also don't see an "unbind" option in Casper and directory bindings fail if the client already believes it is bound, I feel like I am missing something here as well.