Calling all Jamfers (not sure if that's a word for all Jamf Nation members, but it is now haha),
Ok, so like a lot of mac admins out there I've had my share of AD binding breaking in the past, but the information making the rounds regarding "bindpocalypse cve-2021-42287" seems pretty scary. I know that Apple has been encouraging mac admins to get away from AD Binding for a while now, but here's the thing...it has worked really well in terms of being easy and mostly reliable for enterprises, esp. those that like my situation (K-12 public school) have mac labs and not a whole lot of mobile devices (laptops). It has been an easy way to allow AD users to authenticate and mount their network home folders.
There's NOMAD and Jamf Connect...I deployed NOMAD a year or so ago when we were having some binding and there for login issues. It was ok, but I didn't love it. The issue of what happens when users change their AD password on one NOMAD iMac what happens when they try to log into another one? I can't recall the specifics but I think it was cubersome. Also the mounting of network home folders was also an issue--that again I recall had a solution but it wasn't as neat and clean and easy as AD Binding has been--emphasis on has been.
FYI: We don't have Microsoft Azure, our AD is local. Going to Azure is not something that is in the cards for us at this time and honestly we don't have a need for it. I mention this because I know that NOMAD doesn't always play nice with local AD binding.
I'm sure you can all relate to the following: 1.) end users don't like change 2.) change is a pain to implement because of the learning curve (and that's assuming there are no glitches or end user error) 3.) replacing a relatively smooth process with one that requires more steps is something you only do if you don't like yourself :-)
All of that said, does anyone know if the Bindpocalypse is still set to collide with the world of AD Binding on Oct. 11th? Has Microsoft made any statements? Will it be limited to Domain Controllers running specific versions of Windows Server?
If anyone has an extremely clear, step-by-step guide to configuring and deploying NOMAD (that hopefully addresses AD password changes, mounting of network home folders, and other miscellaneous issues), I would be forever grateful. :-)
Please share your thoughts and experiences, suggestions and ideas, and whatever else you might want to contribute!
Thanks in advance!!! :-)