We are needing to bind some M1 Mac Mini's as well as some iMac's we purchased that will be delivered soon.
We're already seeing issues even just binding the Mac Mini's.
I realize the baked-in AD integration isn't the best. We've fought with it in the past, but it's always worked.
I'm barely able to bind a test computer.
I'm reading some people think that something about the M1's is where the problem with AD binding lies:
https://community.jamf.com/t5/jamf-pro/big-sur-active-directory-binding/m-p/242080#M227788
I get 5200 errors that it couldn't contact the authentication server.
If I look through the console the specific error is 'KDC is unreachable - 'unable to reach any KDC in realm __our AD domain__, tried 0 KDCs'
Time is synced.
I've read of this workaround - 'Configuring KDC in krb5.conf' - https://github.com/Microsoft/vscode-mssql/wiki/How-to-enable-Integrated-Authentication-on-macOS-and-Linux-using-Kerberos
But it appears Big Sur doesn't have a krb5.conf file, it has a 'krb5.keytab' file which is different.
I was briefly able to get it bound at some point but it didn't stay bound.
We are using JAMF Connect for some use cases, but binding would be a better option for us in shared lab settings.