Skip to main content
Question

macOS High Sierra 10.13 issues with AD and password changes.

  • September 26, 2017
  • 54 replies
  • 357 views

Show first post

54 replies

Forum|alt.badge.img
  • New Contributor
  • June 8, 2018

Has this been resolved (natively, without workarounds/Nomad/etc) in any recent High Sierra version? Current is 10.3.5 released on 1 Jun at time of writing.


Forum|alt.badge.img+1
  • New Contributor
  • July 24, 2018

No, has not been resolved. Still happens with the latest current version of High Sierra (10.13.6).

The weird this is the work-around I've found. If I bind to AD with Create Mobile Account OFF, I can successfully login to the AD account, then go into System Preferences -> Users & Groups -> user just created, I can click on the button that says "Create Mobile Account", bam sets it up as a Mobile User and works perfectly after that.

I don't understand. Luckily we setup new machines for people ahead of times and can do that.


Forum|alt.badge.img+7
  • Contributor
  • August 30, 2018

@seann @kendalljjohnson We have the same problem. The admin accounts that we control via AD groups don't work. The fix is simple enough but a PITA: unbind AD via script, and then rebind it. Have you managed to automate this to trigger on everyone who's done an update to 10.13?

Thanks in advance.


Forum|alt.badge.img+13
  • Valued Contributor
  • September 10, 2018

For us at least using Config Profiles for the Directory Payload AD Bind and Mobility Payload to enable mobile accounts, the AD password updates but the preboot password is still the old password for a time.
After some time logged in (we haven't been able to narrow this down to a specific amount of time yet), the Preboot password will get updated and be the current password on subsequent reboots.
This has happened on 10.13.6.