I need to setup a few macs on a Windows eco-system. The Macs need to be
connected to Active Directory but also the AD user must not be able to
sign out of a managed apple id or create a local user account to sign in
with their own personal apple id. ...