Skip to main content
Question

Not all AD users showing up in "Scope"

  • September 21, 2015
  • 8 replies
  • 37 views

Forum|alt.badge.img+3

Am trying to make some iPad apps available to a couple of specific users. I've done this many times before, but now when I go into "Scope > Add > Users" it's only showing 506 entries when it should be about 14000.

One of the users I need is in there, the other is not. Both are in AD. Any ideas?

8 replies

Forum|alt.badge.img+3
  • Author
  • New Contributor
  • September 21, 2015

Oh, and it may or may not be related, but on our Casper server (running OS X 10.7.5) I am no longer able to open the JSSDatabaseUtil.jar. When I double click it nothing happens. Was going to try running some database repairs in the hopes of fixing the above issue.

Any ideas on this would also be greatly appreciated. Thanks!


Forum|alt.badge.img+7
  • Contributor
  • September 21, 2015

In our environment, they don't show up unless that user has enrolled a device. Once they do, their AD credentials show up as a scope option in our list.


Forum|alt.badge.img+4
  • Contributor
  • September 22, 2015

Tagging on to what @qhle373 said, you also have to make sure when you assign the device it is assigning to the AD account and not creating it's own local account. Happens if you misspell a username.


Forum|alt.badge.img+12
  • Valued Contributor
  • September 22, 2015

A vendor here reported that Apple's AD plugin has a 1,000 computer/user paging limit…that might be causing what you are seeing…I can send or post sources if you need more info…

I believe it affects OSX 10.7-10.10, but I haven't tested it in a while.


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • September 22, 2015

Ok, that makes sense. Thanks for the replies!

As for the 1,000 computer/user paging limit... that would explain why some issues I'm having with a local website I host from OS X Server and trying to use AD credentials to control who can access which pages. Is there any way around this 1,000 paging limit?


mm2270
Forum|alt.badge.img+24
  • Legendary Contributor
  • September 22, 2015

Yeah, I've seen this too. You can see it directly in the Directory Utility.app. Open the app, make sure the "in node" is set to your AD domain path, then change the "Viewing" to Users or Computers or any other item. After it scans you can see on the bottom of the window it will show "1,000 records" We have over 50k users in AD here, so its definitely not pulling all records - not by a long shot.

I don't know of a way around this limitation.


Forum|alt.badge.img+12
  • Valued Contributor
  • September 22, 2015

According to our vendors, Apple has yet to resolve it and it has been an issue with the Apple AD plugin for many years now….


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • September 23, 2015

@mattschenk I'd add the users to an AD group (in AD), & then limit access using that group.