Adding Windows AD Server to Mac OD Domain

Help...
We are adding an Active Directory server to our network, to assist with larger groups and email issues. Problem is, through searching I've found people who say it is easy and others who say it will just fall apart. But... Nothing concrete about how to properly go about making sure it works the way it is supposed to...
Anyone know of any good articles or documentation about adding in a AD server? Eventually we need to promote it to the master and still have the mac servers as replicas (or at least still part of the system, so we can update them as needed).
Any thoughts?
At this point I have the server up and running, but it will not bind to the OD master.  It keeps complaining about the username and password being wrong (even though they are not, and I've tried many different accounts).  I tried adding the AD server as a replica of the OD master, and that failed as well.  The OD server said that the replica was missing the Server app...
Thanks for any help with this, at all...
--Charles...

Received this from a community member on SpiceWorks forums...
David_CSG  wrote:
It won't work in the direction you're trying to go, never has and isn't even supported. Joining Windows AD to Apple's Open Directory has never been an option from Microsoft, and I would recommend strenuously (even vehemently) against trying at all (via any 3rd-party software) where a Domain Controller is involved. Just don't.
Your best & only option is in the other direction, and is built-in and supported by the Mac OS: Binding FROM the Mac (server or client) to Active Directly.
The best you could do is authenticate your Windows client (only !) machines to Apple's Open Directory via pGina, see http://pgina.org/
That will not provide any AD domain administration features at all as the Apple OD server doesn't even offer them = Group Policy, and more.
http://community.spiceworks.com/topic/563735-integrating-active-directory-into-o ur-mac-mavericks-open-directory-domain?page=1#entry-3684109

Similar Messages

  • Joining Windows 2012 Server to SBS 2011 Domain

    Hi All,
    I have been trying to get a new Windows 2012 Server to join a SBS 2011 domain. The error message I am getting is:
    The following error occurred attempting to join the domain: xxxx. The specified domain does not exist or could not be contacted.
    I have a bunch of other Windows 7/XP workstations that have joined successfully. I have also tried disabling TCP/IP v6 on the 2012 server and joining the domain with the netdom command. The SBS 2011 server is listed as the primary DNS server on the 2012
    server.
    What else can I try here?
    Thanks,
    DR.

    I am having the same issue has the OP. I have my DNS settings pointing to the sbs server that hosts the domain and DNS. I am receiving the same error.
    Server 2012 R2 Standard
    SBS 2011 Essentials
    Jerry T

  • Which is best remote software to access Windows 2008 Server from Mac Air

    Hi
    Is anyone using, succesfully, remote software to log into a Windows Server 2008 network from a Mac. I use Wyse Pocket Cloud Pro on my iPhone but there doesn't seem to be an app for a Mac Air. Any suggestions or help appreciated?

    Ummm... Microsoft's own RDC for Mac
    http://www.microsoft.com/mac/remote-desktop-client

  • Adding windows pcmci card in Mac g4

    Is it possible to plug in a linksys, pcmci wireless g card into the internal airport card on my Mac G4? Is there any harm in trying it to see if it would work?

    Hi-
    I have seen many reports on the web, of Mac users doing well with the Linksys cards. They seem to be Broadcom 54 chip based, which is what Apple uses. It may not report right in your profiler, but it's worth a try.

  • Mac os x wiki server can't authenticate user password from active directory recently after we upgraded to windows 2008 server.

    after upgraded to windows 2008 server, our  mac os x wiki server can't authenticate user password anymore. How can I re-bind the wiki server to the AD again? thanks in advance.

    Solved it by deleting the user and creating a new one with the same userID.
    Maybe it occured because I marked the "user has to change password after first login" box when resetting the password but didn't yet allow him to do so in the webpages menu?!?

  • Upgrade to os x lion, now I cannot print on my windows print server. Please help

    After upgraded to OS X Lion, Now, I cannot print from my windows print server. Mac keep asking for user name and password (never before on 10.6 OS) I tried different user and password, both on my Mac and windows account, none is working.
    I reset printer system and add new printer. try to print and status is still showing "on hold (Authentication required)" and asked for user name and password again.
    I am using Brother HL-2140 connected to my XP Pro 32 bit. Mac is connected to wireless network. Both Mac and PC alredy updated with latest printer drivers.
    My printer was working fine before upgraded to Lion. Please help

    Had the same problem with my windows server 2008 R2 print server.
    I tried to print and i ask me for my password, so i enterd my user account and it workt but every time i had to enter the password. My solution whas entering the administrator credentials.

  • Windows mail server migration

    Hi all,
    I have a client who wants to migrate his windows mail server to Mac OS X Tiger. Is it possible? If yes, how?
    Thanks in advance
    regards,
    Pradeep
      Mac OS X (10.4.4)  

    We migrated from MS Exchange 2000 to OS X Server Mail, just 15 users but tons of gigabytes of mail. What i did:
    -set up IMAP on Exchange 2000 (we already used it), all mail has to be stored on the server
    -set up Mail Service on OS X
    -set up User Accounts on OSX Server, activated Mail for each user
    -synced each user account from an OS X client computer using "imapsync". It works like an IMAP client copying all mail to the new mail server, it can keep the seen flag and does not produce duplicate mails. there is a description how to invoke imapsync automatically for a list of users.
    -did a reconstruct -r on OS X Server to be sure the mailboxes are clean
    you can get imapsync via darwinports.
    it's worth the work...
    PowerMac G5, Dual 2 GHz Mac OS X (10.4.5)

  • Equivalent windows terminal server

    Hi,
    I wish to know if there is an equivalent of windows terminal server on mac OS X SERVER.
    My purpose is to install applications on the server, and that the customers can open session to distance to use the applications.
    Solution ?
    Thanks.

    You can check http://macterminalservers.com/.
    Bye

  • How do I add a Mac to a Windows Server 2003 or 2008 domain?

    I recently started working for a public school district that runs Windows Server 2003 and Windows Server 2008 R2. There are several faculty members, myself included, that would like to get their Macs onto the domain and capable of file sharing, printing to network printers, etc. I cannot find decent instructions anywhere. Could someone please point me in the right direction or give me some directions? It would be greatly appreciated. Thanks.

    I'm also new to the MAC world - I trust you were able to join the MAC's to the domain - I finally figured it out. However, I have not been able to get the MAC's to save to the Windows 2008 server where I have student folders setup. Have you been able to do this? If so can share the info with us.
    Thanks,
    Steve
    [email protected]
    Newport School District

  • When I access a windows files server with the mac I am adding .apple (hidden files). How can I prevent this.

    When I access a windows files server with the mac I am adding .apple (hidden files). How can I prevent this?

    Look for a program called BlueHarvest. I'm not sure if it still works with Mountain Lion.
    I believe your file server can be set up to handle the metadata files, but I suppose that would depend on the Server software and your IT staff.

  • Mac's using a Windows Print Server

    I am an administrator for a dual-platform school district (elementary and middle schools). We run both AD & OD, and all of our Mac's are bound to both AD & OD. Our users authenticate to Active Directory. My issue is printing from our Mac's (MacBooks to be precise). Currently, all of our PC's are printing to a Windows Print Server (Server 2003). When setting up printing on our Mac's, we use IP printing. We use IP printing because when we attempt to install printers via Windows printing, it requires authentication when printing (which I don't understand, since the users is already authenticated to the domain). The real issue is this. Because our Mac's use IP printing, the print queue is local to the machine. So, if anything impedes the print job, it pauses the printer, and in our environment, the only way to un-pause the printer and the local print queue is to log in as the local admin, clear the queue, and un-pause the printer. This is a PITA. I need to find a stable printing environment for our Mac's, and I would prefer to use our existing Windows Print Server.
    Does anyone have any experience in having Mac's print to a Windows Print Server, without having the authentication issue?? I have heard of third-party products such as PaperCut, but I really don't think that's necessary for what we are trying to do.
    Any help would be greatly appreciated.
    Thank you in advance.
    --Russ

    I am running a very similar setup to what you are trying to do. Mine is OD and the windows server (2003 64bit) is bound to the OD.
    My users on both Mac and Windows are printing to and through the windows server, so this way I see and can control everything in the print queues.
    I will try and help you setup.
    Firstly are the printers installed and shared out on your windows server?
    If that is done logon to your windows print server and then logon to *local security policy*. Under *Security Settings* go *Security Options* and look for “*Network security: LAN Manager authentication level*” and changed it to “*Send LM & NTLM responses*”.
    Okay it all and log off your server.
    Now goto a Mac client you want to print from.
    Go the usual way of adding the printer on a Mac but this time do not use IP printing choose windows instead then select your domain in the list. You will then see all the servers on your network now select the print server in the list. If you have shared the printers out when you installed them on the print server you will see the list of printer installed on that server.
    Select the printer you would like to install at this point it may asked you for the user name and password, use the network name and password of the user that will be using that machine and tick to remember password. Because it’s coming from a windows server it will not auto select the correct driver for you. You need to select the correct driver for yourself then click add if you have any extra trays etc you need to manually select them too.
    The printer will be added, the first time you goto print on this printer it will ask you for password again click to remember password.
    Repeat the installation for all the printers you need to add and don’t forget to make a print after each install so you can add the remember tick on the first print.
    If you are using something like keyminder on the mac’s then when the password changes from AD or OD the keychain will automatically be updated by keyminder. If you are running Snow Leopard you do not need keyminder.
    Hope this helps.

  • Cannot join Windows XP machines to the Mac PDC domain

    Frustrated...
    Yesterday, I was able to successfully add 5 Windows XP machines to the Mac PDC Domain (lets call it xyz.lan). Those machines show up as valid computer accounts in Workgroup Mananger (PC1$, PC2$, etc.). Users are able to logon to those Windows XP machines using their Mac Open Directory user account and access their home folder, etc.
    This morning, for some reason, I can no longer join XP machines to the Mac PDC domain. On both PCs I tried it with, I receive a "Insufficient System Resources exist to complete the requested service" on the Windows XP machine. I am using the diradmin user account and password to supply credentials. Same exact process as yesterday (which worked fine).
    A couple things of note. I made sure the PDC domain is set to Enabled for allowing Guest Access and that WINS Registration is also enabled. Authentication is lso set for NTLMv2 and NTLM for enabled. I also tried rebooting the server this morning as well. It's running 10.5.4. This was not an upgrade from 10.4, but a fresh install of Leopard.
    No changes were made on the server between yesterday and today that I am aware of.
    Looking at the /var/log/samba/log.smbd log, there are thousands of entries for "This process has forked and you cannot use this corefunctionality process, You must EXEC()" etc... The log also shows failures when the XP machine tries to join to the domain. Log entries are listed showing, "pdbdefault_createuser: failed to add new account for 'PC6$'". Adding PC6$ manually via Workgroup Manager doesn't help either.
    Any idea what to check next? I read so many varied things about Leopard and SMB not quite playing nice. People mentioning they had to go through all sorts of hurdles to get this working. Any advise is welcome.

    Any news about this? I'm having the same problem trying to join a Vista box to the domain. Here are the logs:
    [2009/04/22 13:25:25, 0, pid=42167] /SourceCache/samba/samba-
    187.8/samba/source/passdb/pdbodsam.c:odssamgetsampwnam(1571)
    opendirectorysamsearchname gave -14136 [eDSRecordNotFound]: no
    dsRecTypeStandard:Computers record for account 'VISTA-02$'[2009/04/22 13:25:25, 0, pid=42167]
    /SourceCache/samba/samba-187.8/samba/source/passdb/pdbodsam.c:odssamgetgrnam(2040)
    odssam_getgrnam gave -14136 [eDSRecordNotFound]: no dsRecTypeStandard:Groups record for
    'VISTA-02$'!
    [2009/04/22 13:25:25, 0, pid=42167] /SourceCache/samba/samba-187.8/samba/source/passdb/pdbodsam.c:odssamgetsampwnam(1571)
    opendirectorysamsearchname gave -14136 [eDSRecordNotFound]: no dsRecTypeStandard:Computers record for account 'VISTA-02$'
    kDSStdAuthNewUser was successful for account "vista-02$"
    kDSStdAuthNewUser accountid len(375)"0x49ef53056eb8a2630000009a00000214,1024 35
    129849767195843988386717130686365750405143149807097035240997923637742337040903
    506153973871003812041813
    324419007326669993686871371821246150609561416487672279816850996014745064297496
    041484464380321772803933500334864635264176672399865926313147079923364167109976
    966344241501266923849093477
    545323065093504527714303 [email protected]"
    <CFArray 0x127bb0 [0xa087e1a0]>{type = mutable-small, count = 1, values = (
    0 : <CFDictionary 0x10fa70 [0xa087e1a0]>{type = mutable, count = 3, capacity = 3, pairs = (
    0 : <CFString 0x127230 [0xa087e1a0]>{contents = "dsAttrTypeStandard:RecordName"} = <CFArray 0x1273d0 [0xa087e1a0]>{type = mutable-small, count = 1, values = (
    0 : <CFString 0x127830 [0xa087e1a0]>{contents = "passwordserver"}
    1 : <CFString 0x12b1b0 [0xa087e1a0]>{contents = "dsAttrTypeStandard:PasswordServerLocation"} = <CFArray 0x1276e0 [0xa087e1a0]>{type = mutable-small, count = 1, values = (
    0 : <CFString 0x128030 [0xa087e1a0]>{contents = "10.10.1.102"}
    3 : <CFString 0x10b150 [0xa087e1a0]>{contents = "dsAttrTypeStandard:AppleMetaNodeLocation"} = <CFArray 0x127b60 [0xa087e1a0]>{type = mutable-small, count = 1, values = (
    0 : <CFString 0x125b80 [0xa087e1a0]>{contents = "/LDAPv3/127.0.0.1"}
    [2009/04/22 13:25:26, 0, pid=42167] /SourceCache/samba/samba-187.8/samba/source/passdb/pdbodsam.c:odssamgetsampwnam(1571)
    opendirectorysamsearchname gave -14136 [eDSRecordNotFound]: no dsRecTypeStandard:Computers record for account 'VISTA-02$'
    [2009/04/22 13:25:26, 1, pid=42167] /SourceCache/samba/samba-187.8/samba/source/passdb/pdbinterface.c:pdb_default_createuser(371)
    pdbdefault_createuser: failed to add a new account for 'VISTA-02$'
    [2009/04/22 13:25:30, 2, pid=42171] /SourceCache/samba/samba-187.8/samba/source/smbd/reply.c:reply_special(328)
    netbios connect: name1=10.10.1.102 name2=MYMAC
    [2009/04/22 13:25:30, 2, pid=42171] /SourceCache/samba/samba-187.8/samba/source/smbd/reply.c:reply_special(335)
    netbios connect: local=10.10.1.102 remote=mymac, name type = 0
    [2009/04/22 13:25:30, 2, pid=42171] /SourceCache/samba/samba-187.8/samba/source/lib/module.c:dosmb_loadmodule(64)
    Module '/usr/lib/samba/auth/odsam.dylib' loaded
    Thanks!
    Message was edited by: capc

  • Can't connect my Mac to my Windows 2003 server shares via SMB

    Hello all
    So my problem is I have my Powerbook running 10.4.7 with all the latest security updates and I cannot connect it to any shares on my Windows 2003 domain controller. Everything was working fine and I could connect to the server with no problem till about a month ago. However, I can still connect to the Windows 2000 domain controller with no problem. The error I get when trying to connect is "Could not connect to the server because the name or password is not correct". I did try clearing out my keychain, making sure all of the authentication policies on the server are correct (disabling the digitally sign commucations always policy), and I even went as far as editing a .conf file in /etc/ folder that allows for passwords to be sent without any encryption (I forget exactly what I changed but I can post that later when I get home from work) and none of this has worked. I unfortunately don't have another mac to test out connecting to the Windows 2003 server. Does anyone have any ideas of what I could do to try and get this issue resolved?

    TO share out as afp you need to have file and print services for macintosh installed on the 2k3 Server.
    O n the main management console click on the shares icon on the left. then click the "link" create a share. The wizard will guide you through the process. i forget the order of progression but i beleive its the second or third part in the dialog it will have 2 check boxes, the top one checked by default, is to share it for windows/smb the second (lower box) is to share as AFP for mac check this box and change the share name if you like. then proceed through the rest of the wizard. Make sure you configure the security/sharing prefs for access.. we typically remove the everyone policy and add one for Authenitcated Users, and ofcourse Administrators.

  • Is it possible for a mac to run across a Windows based server such as in a school, and still be able to access all networked folders? I have been told that macs can only read down a certain number of folders

    Is it possible to run a mac on a windows based server? We have a server based on Windows 7 in our school, and our techies are reluctant to let me buy a mac as they say macs can only read a number of folders deep, which would preclude me from accessing shared folders on our servers. Is this true, and is there a way round this? I would eventually like to get a suite of macs, but because all our resources are on the server, I have to be able to access them.
    Thanks for any help,
    Mike

    I have found that both Linux and Mac (unix) are capable of reading "deep" folders while win 32 will have issues, your it people are clearly wrong.  I run a network with both win/mac. And as long as the win servers/pc's that have shares are set to allow apple file sharing in their folder properties.   And the macs are set to allow smb there should absolutely no trouble with you accessing anything across the platforms, heck, from a Mac to a win pc on some occasions you don't even need to include a "domain" name to log on to, and you can create aliases and make your own shortcuts etc... So you don't have to manually connect each time you boot up etc... But that's all personal preferences I suppose.
    All I can tell you is that, I do it on a daily basis managing a small business. So your answer is yes you can.

  • Windows storage server 2008 R2 : i have an Issue with limiting acces group in a domain

    Hi,
    I have a NAS with Windows storage server 2008 r2. I have added it in my domain and i have check the check
    box – Allow access only to users in the following group: but i can select the groups i want to add it doesn’t appear in the selection box.
    My user is not a domain administrator.

    Hi,
    à
    but i can select the groups i want to add it doesn’t appear in the selection box.
    Would you please let me know which group you want to select? Anything special? Would you please provide a screenshot
    of this issue (please hide all protected or private information)?
    à
    My user is not a domain administrator.
    Did you mean that do above operation (select a group) via a non-administrator account? Please use an administrator
    account to select group and check if find that specific group.
    If any update, please feel free to let me know.
    Hope this helps.
    Best regards,
    Justin Gu

Maybe you are looking for