Posted on 01-29-2024 10:50 AM
Hello guys, we have users where the Network AD password gets out of sync with the mac when the user changes the password every 3 months or so. We have a Self Service action that updates their network password with their mac log-in password however users do not use that very often. The macs are file vaulted, how do you guys sync the network passwords with the mac log-in passwords? Is there an easier way to do that?
Posted on 01-29-2024 11:02 AM
NoMAD / JAMF Connect / XCreds
Posted on 01-29-2024 11:26 AM
Thank you, is NoMAD free? Is it better than thet wo?
Posted on 01-29-2024 11:38 AM
its been a long time since I've used NoMAD.. possibly been sunset by JAMF.. but its free.. XCreds is 3$ per client / per year.. JAMF Connect.. time to ask your vendor for a package deal.. but its not cheap..
Being on local AD now NoMAD might work, but plan for the future..
01-29-2024 11:33 AM - edited 01-29-2024 11:34 AM
@Mouthbaten_1911 Is your AD system on-prem or Azure AD (or whatever MS calls it these days). If it's on-prem you can use the Kerberos SSO plug-in which is part of macOS to sync the Mac's local password: https://support.apple.com/guide/deployment/kerberos-sso-extension-depe6a1cda64/web
Posted on 01-29-2024 11:34 AM
It's on-prem, we haven't moved over to Azure AD yet.
Posted on 01-29-2024 12:03 PM
You should definitely look into enabling the Kerberos SSO extension on your Macs then
Posted on 01-29-2024 12:37 PM
How do you enable Kerberos SSO extension? Are there any instructions?
Posted on 01-29-2024 12:58 PM
Enable it with the Single Sign On Extensions payload in a Configuration Profile.
The main piece of information you need to enable it is your Kerberos Realm. It should be entered in ALL CAPS format in the profile. There are a ton of other options you will need to look thru when turning it on, but the other two options that you should enable are "Local password sync" and "Password expiration notification"
Posted on 01-29-2024 01:08 PM
We also have Mobile accounts on the macs.
Posted on 01-29-2024 01:26 PM
Ok, so, are you saying these are mobile accounts are not getting passwords synced, and causing login issues? Not local accounts? Because actual mobile accounts should stay in sync with AD, because they are tied to AD, not the local domain.
I can see them getting out of sync with FileVault though.
If this is your case, honestly, the only advice I have is to drop the use of mobile accounts. Apple really doesn't support those anymore, so you're kind of in unsupported territory now. You really should use local accounts and the Apple SSO/Kerberos extension as a next transition step to move away from your current setup. I know that's easier said than done, but I don't foresee any easy ways of ensuring that Macs using cached AD mobile accounts and FileVault will work well together.
Posted on 01-29-2024 01:31 PM
Yes they are Filevaulted, Thanks for your info I will take this up with the management.