Posted on 07-17-2009 11:47 AM
Hello all. I have recently been using Casper's account settings to bind the
computers in one of our labs to both Active and Open Directory. AD binding
is going flawlessly, however when we bind a computer to OD any managed
preferences enforced at the user level are ignored. When a computer is bound
manually to OD using directory utility managed preferences work perfectly,
but if Casper does the binding only preferences enforced by computer group
work. After a computer has been bound to OD by Casper, even if it is unbound
and removed in workgroup manager then rebound
manually, no user based preferences, such as disabling student access
to system prefs, can be enforced without reimaging the mac.
All preferences are managed through workgroup manager, not Casper's managed
preferences settings. Has anyone encountered this problem, or have any ideas
why it would be happening?
Thanks in advance,
Alex Madden
--
Enter no conflict against fanatics unless you can defuse them. Oppose a
religion with another religion only if your proofs (miracles) are
irrefutable or if you can mesh in a way that the fanatics accept you as
god-inspired. This has long been the barrier to science assuming a mantle of
divine revelation. Science is so obviously man-made. Fanatics know where you
stand, but more important, must recognize who whispers in your ear.
Missionaria Protectiva Primary Teaching
Chapterhouse: Dune
Posted on 07-20-2009 07:00 AM
Alex,
This is properly working as computer group policy overrides individual group policies in WGM and MCX. To get around this you can create a 'guest' computer in WGM and completely unmanage the computer. Then when you bind your Mac clients, do not do authenticated binds with the computer name so the computer will not show up in WGM and therefore not pick up any policies for that computer and pick up off the guest computer. I hope that makes sense.
-Tom