Hey guys,
I am having integrating our Mac's into Active Directory.
I am able to:
-- Join Mac's to the domain (with no problems)
-- Log in to the domain with an AD authenticated user
Main Problem: -- When logging in as an Active Directory user, it normally takes 3 - 5 minutes to authenticate (no exaggeration). This happens whether or not it has been enrolled in JSS.
Possible Cause: We have a large AD structure (over 200,000 computer objects + associated users) and I suspect that it may be trying to scan the whole structure when it logs in. Is there a way we can limit the AD scope or somehow reduce the login time to something more reasonable, like under 30 seconds?
Any ideas?
Thanks!
