Sync network password with Mac login password?

Mouthbaten_1911
New Contributor III

Hello guys, we have users where the Network AD password gets out of sync with the mac when the user changes the password every 3 months or so. We have a Self Service action that updates their network password with their mac log-in password however users do not use that very often. The macs are file vaulted, how do you guys sync the network passwords with the mac log-in passwords? Is there an easier way to do that? 

11 REPLIES 11

jamf-42
Valued Contributor II

NoMAD / JAMF Connect / XCreds 

Thank you, is NoMAD free? Is it better than thet wo? 

jamf-42
Valued Contributor II

its been a long time since I've used NoMAD.. possibly been sunset by JAMF..  but its free..  XCreds is 3$ per client / per year.. JAMF Connect.. time to ask your vendor for a package deal.. but its not cheap.. 

Being on local AD now NoMAD might work, but plan for the future.. 

sdagley
Esteemed Contributor II

@Mouthbaten_1911 Is your AD system on-prem or Azure AD (or whatever MS calls it these days). If it's on-prem you can use the Kerberos SSO plug-in which is part of macOS to sync the Mac's local password: https://support.apple.com/guide/deployment/kerberos-sso-extension-depe6a1cda64/web

It's on-prem, we haven't moved over to Azure AD yet.

sdagley
Esteemed Contributor II

You should definitely look into enabling the Kerberos SSO extension on your Macs then

How do you enable Kerberos SSO extension? Are there any instructions? 

mm2270
Legendary Contributor III

Enable it with the Single Sign On Extensions payload in a Configuration Profile.

The main piece of information you need to enable it is your Kerberos Realm. It should be entered in ALL CAPS format in the profile. There are a ton of other options you will need to look thru when turning it on, but the other two options that you should enable are "Local password sync" and "Password expiration notification"

Screen Shot 2024-01-29 at 3.56.45 PM.png

We also have Mobile accounts on the macs. 

mm2270
Legendary Contributor III

Ok, so, are you saying these are mobile accounts are not getting passwords synced, and causing login issues? Not local accounts? Because actual mobile accounts should stay in sync with AD, because they are tied to AD, not the local domain.

I can see them getting out of sync with FileVault though.

If this is your case, honestly, the only advice I have is to drop the use of mobile accounts. Apple really doesn't support those anymore, so you're kind of in unsupported territory now. You really should use local accounts and the Apple SSO/Kerberos extension as a next transition step to move away from your current setup. I know that's easier said than done, but I don't foresee any easy ways of ensuring that Macs using cached AD mobile accounts and FileVault will work well together.

Yes they are Filevaulted, Thanks for your info I will take this up with the management.