TweetFollow Us on Twitter

MacEnterprise: Integrating with Active Directory

Volume Number: 25
Issue Number: 04
Column Tag: MacEnterprise

MacEnterprise: Integrating with Active Directory

A look at third-party tools for leveraging your AD infrastructure

By Greg Neagle, MacEnterprise.org

Introduction

In enterprise environments, Microsoft's Active Directory is possibly the single-most common directory service. It's well suited to large companies with geographically separated locations, and scales very well to tens and even hundreds of thousands of users. In any organization that has many Windows computers, or any company that uses Exchange, it is the obvious and maybe unavoidable choice for a directory service. For these reasons and more, Active Directory is the 500-pound gorilla of directory services. Questions about integrating Mac OS X with Active Directory are among the most common questions on the MacEnterprise mailing list (http://www.macenterprise.org/mailing-list).

Given the ubiquity of Active Directory in enterprise environments, it's not surprising that Apple offers a solution for AD integration: the Active Directory plug-in for Directory Services. This plug-in has been covered well here and elsewhere: Michael Bartosh wrote an excellent article for the November 2004 issue of MacTech covering the AD plug-in that shipped with Panther. You can find it in MacTech's online archives - much of what it covers is still relevant. In October 2007, Philip Reinhart covered a few more tricks with using the AD plug-in and the dsconfigad command-line tool. And of this writing, Apple has an excellent whitepaper on integrating Mac OS X with Active Directory available here: http://images.apple.com/business/solutions/it/docs/Best_Practices_Active_Directory.pdf

Still, Apple's built-in solution does not meet every possible need you might have when integrating Macs into an existing Active Directory infrastructure. Fortunately, there are third-party tools that can be used to supplement or even replace Apple's tools. We'll look at a few in this article. While not intended to be a in-depth examination, we'll briefly touch on the main features of some of the third-party solutions.

What's missing?

Before we look at third-party tools, it makes sense to talk about some of the "missing features" from Apple's offerings. Get ready for some three-letter acronyms:

GPO

GPOs, or Group Policy Objects, are used by Active Directory administrators to help manage their Windows clients. They can be used to manage security policies, software installation, login scripts, folder redirection, and some application settings. They are similar in concept to MCX settings in managed OS X environments. Some organizations would like to be able to define GPO settings to manage Macs along with their Windows machines. Apple's AD plug-in doesn't support Active Directory GPOs.

MCX

MCX is Apple's client management framework. Out-of-the box, there is no support for MCX settings in Active Directory. Some MCX options include extending the AD schema to include MCX attributes, deploying a dual-directory infrastructure where MCX records are stored in a secondary directory, or using a third-party replacement for Apple's AD plug-in.

DFS

DFS, or Microsoft's Distributed File System (sometimes written "Dfs") is a method of making shared filesystems available via a network. This is typically used to provide fault-tolerance and/or redundancy, and to insulate users from having to know on which fileserver a given resource is located. It is roughly equivalent to automounted NFS shares where a resource can be accessed by a specific path, no matter which actual fileserver hosts it. While this is not really a function of the AD plug-in, Apple's built in SMB/CIFS client does not support Microsoft's DFS.

This is not an exhaustive list - certainly there are other features of Active Directory and Windows file services that are not supported by Apple's tools, or with which Apple's tools have difficulty.

Select Third-party tools

ADmitMac

Thursby Software has been providing tools to help Macs connect to Windows for many years. ADmitMac, currently at version 4, is a complete replacement for both Apple's AD plugin and the built-in SMB client. Some key features:

Requires no Active Directory schema changes

Supports DFS, even for home directories

Support for Active Directory shared printers

Support for MCX client management

More information is available at http://www.thursby.com/products/admitmac.html

DAVE

Another product from Thursby Software is DAVE. It implements a subset of the features in ADmitMac. It operates as a replacement for Apple's SMB client, but provides less integration with Active Directory. See http://www.thursby.com/products/dave.html to learn more.

DirectControl

DirectControl from Centrify is also an Active Directory plug-in replacement. Besides the obligatory support for Active Directory authentication, a major feature of interest is support for GPOs: Windows administrators can use standard Windows tools to define GPOs for Mac clients that can specify certain management settings for user and computers. The ability to use a single set of tools to manage users, groups, and manage computers, no matter the OS is an important one for some organizations. Centrify also offers DirectControl for Linux and UNIX, which offers the possibility of using Active Directory to authenticate and manage all your platforms. More information on the Mac product is available at http://www.centrify.com/directcontrol/mac_os_x.asp

Likewise Enterprise

Likewise Enterprise is yet another replacement for Apple's Active Directory plug-in. A unique feature of this product is the ability to store MCX data in Active Directory without extending the schema. This is similar in concept to what Centrify's DirectControl does, but with two important differences:

Administrators can not only define Group Policy Objects using the Microsoft Management Console, but they can also use Apple's Workgroup Manager application to define Mac-specific management settings

Because actual MCX data can be stored in AD, a wider range of management settings are supported.

Likewise Enterprise is also available for Linux and UNIX, again making it possible to use a single directory service for all your platforms. Additionally, Likewise offers an Active Directory management console that runs on Mac OS X and Linux. Visit http://www.likewise.com/products/likewise_enterprise/ for more information on this product.

ExtremeZ-IP

ExtremeZ-IP is a product from GroupLogic that provides Apple File Protocol services and printing services from Windows servers. Implementing ExtremeZ-IP on your Windows file servers allows Mac clients to connect via the native AFP client instead of the SMB/CIFS client. Since this is a server-based file sharing solution, it might seem odd to include it in this list of third-party tools. But GroupLogic has announced that Extreme-IP 6, due this year, will provide support for Microsoft DFS. With ExtremeZ-IP 6, Leopard (and later) clients will be able to use AFP to connect to Microsoft DFS shares. As a server-based solution, it can be used in conjunction with many of the client-based solutions mentioned above. You can find out more about ExtremeZ-IP at http://www.grouplogic.com/products/extremeZ-IP/

Active Directory Integration Cheat Sheet

To wrap things up for this overview, the table below lists the solutions mentioned in this article with a matrix of some of the features not directly supported by Apple's built-in tools. If Apple's bundled solutions for Active Directory and Windows file server integration don't meet all your needs, you have some additional options to explore!


Greg Neagle is a member of the steering committee of the Mac OS X Enterprise Project (macenterprise.org) and is a senior systems engineer at a large animation studio. Greg has been working with the Mac since 1984, and with OS X since its release. He can be reached at gregneagle@mac.com.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

Latest Forum Discussions

See All

Go from lowly lizard to wicked Wyvern in...
Do you like questing, and do you like dragons? If not then boy is this not the announcement for you, as Loongcheer Game has unveiled Quest Dragon: Idle Mobile Game. Yes, it is amazing Square Enix hasn’t sued them for copyright infringement, but... | Read more »
Aether Gazer unveils Chapter 16 of its m...
After a bit of maintenance, Aether Gazer has released Chapter 16 of its main storyline, titled Night Parade of the Beasts. This big update brings a new character, a special outfit, some special limited-time events, and, of course, an engaging... | Read more »
Challenge those pesky wyverns to a dance...
After recently having you do battle against your foes by wildly flailing Hello Kitty and friends at them, GungHo Online has whipped out another surprising collaboration for Puzzle & Dragons. It is now time to beat your opponents by cha-cha... | Read more »
Pack a magnifying glass and practice you...
Somehow it has already been a year since Torchlight: Infinite launched, and XD Games is celebrating by blending in what sounds like a truly fantastic new update. Fans of Cthulhu rejoice, as Whispering Mist brings some horror elements, and tests... | Read more »
Summon your guild and prepare for war in...
Netmarble is making some pretty big moves with their latest update for Seven Knights Idle Adventure, with a bunch of interesting additions. Two new heroes enter the battle, there are events and bosses abound, and perhaps most interesting, a huge... | Read more »
Make the passage of time your plaything...
While some of us are still waiting for a chance to get our hands on Ash Prime - yes, don’t remind me I could currently buy him this month I’m barely hanging on - Digital Extremes has announced its next anticipated Prime Form for Warframe. Starting... | Read more »
If you can find it and fit through the d...
The holy trinity of amazing company names have come together, to release their equally amazing and adorable mobile game, Hamster Inn. Published by HyperBeard Games, and co-developed by Mum Not Proud and Little Sasquatch Studios, it's time to... | Read more »
Amikin Survival opens for pre-orders on...
Join me on the wonderful trip down the inspiration rabbit hole; much as Palworld seemingly “borrowed” many aspects from the hit Pokemon franchise, it is time for the heavily armed animal survival to also spawn some illegitimate children as Helio... | Read more »
PUBG Mobile teams up with global phenome...
Since launching in 2019, SpyxFamily has exploded to damn near catastrophic popularity, so it was only a matter of time before a mobile game snapped up a collaboration. Enter PUBG Mobile. Until May 12th, players will be able to collect a host of... | Read more »
Embark into the frozen tundra of certain...
Chucklefish, developers of hit action-adventure sandbox game Starbound and owner of one of the cutest logos in gaming, has released their roguelike deck-builder Wildfrost. Created alongside developers Gaziter and Deadpan Games, Wildfrost will... | Read more »

Price Scanner via MacPrices.net

13-inch M2 MacBook Airs in stock today at App...
Apple has 13″ M2 MacBook Airs available for only $849 today in their Certified Refurbished store. These are the cheapest M2-powered MacBooks for sale at Apple. Apple’s one-year warranty is included,... Read more
New today at Apple: Series 9 Watches availabl...
Apple is now offering Certified Refurbished Apple Watch Series 9 models on their online store for up to $80 off MSRP, starting at $339. Each Watch includes Apple’s standard one-year warranty, a new... Read more
The latest Apple iPhone deals from wireless c...
We’ve updated our iPhone Price Tracker with the latest carrier deals on Apple’s iPhone 15 family of smartphones as well as previous models including the iPhone 14, 13, 12, 11, and SE. Use our price... Read more
Boost Mobile will sell you an iPhone 11 for $...
Boost Mobile, an MVNO using AT&T and T-Mobile’s networks, is offering an iPhone 11 for $149.99 when purchased with their $40 Unlimited service plan (12GB of premium data). No trade-in is required... Read more
Free iPhone 15 plus Unlimited service for $60...
Boost Infinite, part of MVNO Boost Mobile using AT&T and T-Mobile’s networks, is offering a free 128GB iPhone 15 for $60 per month including their Unlimited service plan (30GB of premium data).... Read more
$300 off any new iPhone with service at Red P...
Red Pocket Mobile has new Apple iPhones on sale for $300 off MSRP when you switch and open up a new line of service. Red Pocket Mobile is a nationwide MVNO using all the major wireless carrier... Read more
Clearance 13-inch M1 MacBook Airs available a...
Apple has clearance 13″ M1 MacBook Airs, Certified Refurbished, available for $759 for 8-Core CPU/7-Core GPU/256GB models and $929 for 8-Core CPU/8-Core GPU/512GB models. Apple’s one-year warranty is... Read more
Updated Apple MacBook Price Trackers
Our Apple award-winning MacBook Price Trackers are continually updated with the latest information on prices, bundles, and availability for 16″ and 14″ MacBook Pros along with 13″ and 15″ MacBook... Read more
Every model of Apple’s 13-inch M3 MacBook Air...
Best Buy has Apple 13″ MacBook Airs with M3 CPUs in stock and on sale today for $100 off MSRP. Prices start at $999. Their prices are the lowest currently available for new 13″ M3 MacBook Airs among... Read more
Sunday Sale: Apple iPad Magic Keyboards for 1...
Walmart has Apple Magic Keyboards for 12.9″ iPad Pros, in Black, on sale for $150 off MSRP on their online store. Sale price for online orders only, in-store price may vary. Order online and choose... Read more

Jobs Board

DMR Technician - *Apple* /iOS Systems - Haml...
…relevant point-of-need technology self-help aids are available as appropriate. ** Apple Systems Administration** **:** Develops solutions for supporting, deploying, Read more
Omnichannel Associate - *Apple* Blossom Mal...
Omnichannel Associate - Apple Blossom Mall Location:Winchester, VA, United States (https://jobs.jcp.com/jobs/location/191170/winchester-va-united-states) - Apple Read more
Operations Associate - *Apple* Blossom Mall...
Operations Associate - Apple Blossom Mall Location:Winchester, VA, United States (https://jobs.jcp.com/jobs/location/191170/winchester-va-united-states) - Apple Read more
Cashier - *Apple* Blossom Mall - JCPenney (...
Cashier - Apple Blossom Mall Location:Winchester, VA, United States (https://jobs.jcp.com/jobs/location/191170/winchester-va-united-states) - Apple Blossom Mall Read more
IT Systems Engineer ( *Apple* Platforms) - S...
IT Systems Engineer ( Apple Platforms) at SpaceX Hawthorne, CA SpaceX was founded under the belief that a future where humanity is out exploring the stars is Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.