Using Active Directory groups to admin

Andrew_Baker
New Contributor

Hello,

We use JAMFschool and bind our Macs to AD via a policy pushed to all the machines. It allows the devices to login however despite putting group names in the profile we still cannot administer through AD accounts. Anyone have any insight on this? It would be most appreciated.

2 REPLIES 2

dlondon
Valued Contributor

I think this bit is the same as for Jamf pro

In the Jamf School doc's here: https://docs.jamf.com/jamf-school/deploy-guide-docs/Binding_Computers_to_Active_Directory_or_Open_Directory.html

It's the Allow Administration field you want to populate with those group names from AD

user-joRWFBbOUw
New Contributor

Default groups, such as the Domain Admins group, are security groups that are created automatically when you create an Active Directory domain. You can use these predefined groups to help control access to shared resources and to delegate specific domain-wide administrative roles.