Can't log in to Profile Manager or My Devices with Active Directory logins

I have an OSX Lion 10.7.4 Server set up with Profile Manager and it is joined to AD.
I am able to see AD groups in the Profile Manager groups section.
I can also see and add AD users and groups using the server app.
I have enabled the "Can Enable Remote Management" check box for Domain Users through Profile Manager. I have also added Domain Admins to the Workgroup group in the Server app. I'm not sure that I want or need either of these options, but they were suggestions to try.
I am not able to log on to the Profile Manager or My Devices pages with AD logins.
I found these directions about nested groups in Workgroup Manager http://krypted.com/iphone/integrating-mac-os-x-lion-servers-profile-manager-with -active-directory/ but I don't have a com.apple.access_devicemanagement local group or any groups like are shown in the picture.
Any ideas what I'm missing?
Cheers,
Ian

I found the two pieces I was missing:
1) Install the Lion Server Admin Tools
Launch the Server Admin App
Click on the server name in the left pane
Click on the Access button in the upper part of the window
Click on Profile Manager
Either manually add specific groups to the list or if you're feeling brave choose the "Allow all users and groups" radio button
2) Run the command line steps on this page to change the authentication to plain text to support AD authentication:
http://support.apple.com/kb/HT4837
Voila!

Similar Messages

  • Cakll Manager 4.1 compatibility with Active Directory 2008

    I need to know the compatibility
    between windows 2008 Active Directory and Call Manager 4.1. I was told Call Manager
    4.1 was incompatibile with windows 2008 AD. Is that Active Directory
    2008 Domain and Forest functional level? I'm moving forw
    ard with replacing all our windows 2003 DCs with Windows 2008 DCs. The question is will
    call manager 4.1 be compatible? Need actual windows 2003 DC or can WIndows 200
    3 forest and domain functional level enough?

    Hello gentlemen,
    I just wanted to let you know that we actually got everything working again on our test bed environment.The DC is running on a virtualized Windows Server 2008 but with the forest and domain functional levels at 2003. What we had to do to resolve the ICM issues (Roggers, PGs and AW/HDS) was for all of the services that wouldn't automatically start, we had to update the 'log on as' settings to re-add those accounts and re-enter the passwords. Also, when running the ICMSetup util, it came back with an error saying that it couldn't see the 'Call Center Applications' OU even though it existed. To resolve that, we ran ICMSetup again, added the ICM instance, then upon going back to the main screen, exiting then re-running ICMSetup, everything worked again and the error did not re-occur. We were able to click on the various instance components (PG1A, CG1A, etc) where as before doing that, those instances were greyed out.
    For our CallManager server 4.1(3) we didn't need to resolve anything on it. It appears to be running ok and phones are registered to it as well.
    Mind you, this is a test bed environment, and the old test bed DC was created a few years ago, and with this new one being a copy of our existing production DC, there were many changes and updates done to it, so that's probably why the old accounts weren't recognized and new ones were created.
    We don't think that will happen in our production environment, but even so, we're not going to upgrade our production DCs to Windows Server 2008 just yet.
    Thanks for the feed back.
    Joe

  • Cisco Call Manager intergration with Active Directory

    We have Cisco Voip which is currently not intergrated with AD. The data (users) in Call Manager have not been updated, (ie if someone left the organisation the ICT department were never told and the new starter took over) I have been asked to intergrate this with active directory and then look in ad and resolve any discrepancies. Has anyone ever completed something similar. Any advise or imput would be gratefully appreicated. Thank You

    Just make sure all the users you want to keep in CUCM are in AD and use the exact same userID or whatever field you'll use for the integration. Those users will just be updated with the AD info and any dependencies they have in CUCM will be there.
    Users that do not have a matching ID in AD will be deleted.
    HTH
    java
    If this helps, please rate
    www.cisco.com/go/pdihelpdesk

  • Can I set up my new iPad as new device with my original Apple id then transfer which apps etc I want later from my cloud, thank you

    Can I set up my new iPad as new device with my original Apple id then transfer which apps etc I want later from my cloud, thank you

    You can download the apps again by opening App Store app on the iPad and tap Purchased at the bottom. That will display all apps that you have previously purchased on that Apple ID and you can download any of them by using the icon to the right of each (icon of a cloud with a down arrow).

  • Hello all...is there a way to activate(on startup) /deactivate(on logoff) CS6 Suite using a script, Active Directory Login Script or central Management Tool?

    hello all...is there a way to activate(on startup) /deactivate(on logoff) CS6 Suite using a script, Active Directory Login Script or central Management Tool?

    The long answer is: No. this is Adobe's secret sauce and you cannot manage it using other tools.
    Mylenium

  • Can't log into any desktop manager KDM set autologin

    Hello, new Arch user. I moved over from Ubuntu.
    I installed arch on my laptop with KDE, LXDE, and Gnome. I had KDE and LXDE set up and working the way I wanted. I tried to log into Gnome. "Something" is wrong with Gnome (no idea at this point). It simply hangs at a black screen.
    I had set KDM to autologin. Now I can't log in, log out, or change desktop environments. I don't know how to turn off the autologin (I turned it on when I was logged into KDE), or force KDM to switch back to a desktop manager that works.
    I found my kdmrc (/usr/share/config/kdm/kdmrc). It indicates autologin is disabled.
    I can get to a shell (ctrl-alt-F#). I can't get to any working graphical environment.
    [General]
    ConfigVersion=2.4
    ConsoleTTYs=tty1,tty2,tty3,tty4,tty5,tty6
    GreeterUID=kdm
    PidFile=/var/run/kdm.pid
    ReserveServers=:1,:2,:3
    ServerVTs=-7
    StaticServers=:0
    [Shutdown]
    BootManager=None
    HaltCmd=/sbin/shutdown -h -P now
    RebootCmd=/sbin/shutdown -r now
    [X-*-Core]
    AllowNullPasswd=false
    AllowRootLogin=false
    AllowShutdown=Root
    AutoReLogin=false
    ClientLogFile=.xsession-errors-%d
    Reset=/etc/kde4/kdm/Xreset
    Session=/etc/kde4/kdm/Xsession
    Setup=/etc/kde4/kdm/Xsetup
    Startup=/etc/kde4/kdm/Xstartup
    [X-*-Greeter]
    AntiAliasing=false
    ColorScheme=
    FaceSource=AdminOnly
    FailFont=Sans Serif,10,-1,5,75,0,0,0,0,0
    GUIStyle=Oxygen
    GreetFont=Serif,20,-1,5,50,0,0,0,0,0
    GreetString=Welcome to %s at %n
    GreeterPos=50,50
    HiddenUsers=
    Language=en_GB
    LogoArea=Logo
    LogoPixmap=/usr/share/kde4/apps/kdm/pics/kdelogo.png
    MaxShowUID=29999
    MinShowUID=1000
    Preloader=/usr/bin/preloadkde
    SelectedUsers=
    ShowUsers=NotHidden
    SortUsers=true
    StdFont=Sans Serif,10,-1,5,50,0,0,0,0,0
    Theme=/usr/share/kde4/apps/kdm/themes/oxygen
    UseBackground=true
    UseTheme=true
    UserCompletion=false
    UserList=true
    [X-:*-Core]
    AllowNullPasswd=true
    AllowShutdown=All
    NoPassEnable=false
    NoPassUsers=
    ServerArgsLocal=-br -nolisten tcp
    ServerCmd=/usr/bin/X
    [X-:*-Greeter]
    AllowClose=true
    DefaultUser=suemiller
    FocusPasswd=true
    LoginMode=DefaultLocal
    PreselectUser=Previous
    [X-:0-Core]
    AutoLoginEnable=false
    AutoLoginLocked=false
    AutoLoginUser=
    ClientLogFile=.xsession-errors
    [Xdmcp]
    Enable=false
    Willing=/etc/kde4/kdm/Xwilling
    Last edited by SueMiller (2014-12-03 13:52:21)

    You don't need to login with the master password. When you get to the log in screen, just log in as you would normally.

  • Cannot log back into Profile Manager

    Okay, so I bought a new Mac mini with Lion server. Three times now I have installed and configured it. When I go to Server/Profile Manager it has my user ID and password from my keychain. I cannot get back into profile manager no matter what I do. This seems to be after I update the software though not sure if this is what is causing it.
    Basically it renders the whole server useless to me if I can't get back in to activate services.

    Hi,
    The behavior could be caused by domain group policy settings, I would suggest you double check group policy settings by running command below:
    GPresult /h filepath:filename.
    More information for you:
    Gpresult
    https://technet.microsoft.com/en-us/library/cc733160.aspx?f=255&MSPPError=-2147217396
    Best Regards,
    Amy
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Can't log into Oracle Application Manager

    I just finished installing Oracle Apps 11.5.9 on Windows 2K Advanced Server with the Vision database. The install went without any problems. However, when I tried to log into OAM I get an Internel Server Error. The error.log file for Apache has the following error:
    [error] [client 192.168.0.16] Filename is not valid: h:/oracle/prodcomn/portal/prod_ora-apps/redirecturl$url=$|servlets$|weboam$|oam$|oamapps$$target$=prod
    In the jserv log file (mod_jserv)
    (ERROR) ajp12: Servlet Error: <blockquote><b><br>java.lang.NullPointerException
    <br></b> at oracle.apps.oam.servlet.ui.handlers.systems.CriticalActivityHandler.doHGridEvent(CriticalActivityHandler.java:87)
    <br> at java.lang.reflect.Method.invoke(Native Method)
    <br> at oracle.cabo.servlet.event.MethodEventHandler.handleEvent(Unknown Source)
    <br> at oracle.cabo.servlet.event.TableEventHandler.handleEvent(Unknown Source)
    <br> at oracle.cabo.servlet.event.TableEventHandler.handleEvent(Unknown Source)
    <br> at oracle.cabo.servlet.event.BasePageFlowEngine.handleRequest(Unknown Source)
    <br> at oracle.apps.oam.servlet.ui.oamPageFlowEngine.handleRequest(oamPageFlowEngine.java:370)
    <br> at oracle.cabo.servlet.AbstractPageBroker.handleRequest(Unknown Source)
    <br> at oracle.cabo.servlet.ui.BaseUIPageBroker.handleRequest(Unknown Source)
    <br> at oracle.cabo.servlet.event.BasePageFlowEngine.processForwardRequest(Unknown Source)
    <br> at oracle.cabo.servlet.event.TrivialPageFlowEngine.getPage(Unknown Source)
    <br> at oracle.apps.oam.servlet.ui.oamPageFlowEngine.getPage(oamPageFlowEngine.java:128)
    <br> at oracle.cabo.servlet.event.BasePageFlowEngine.handleRequest(Unknown Source)
    <br> at oracle.apps.oam.servlet.ui.oamPageFlowEngine.handleRequest(oamPageFlowEngine.java:370)
    <br> at oracle.cabo.servlet.AbstractPageBroker.handleRequest(Unknown Source)
    <br> at oracle.cabo.servlet.ui.BaseUIPageBroker.handleRequest(Unknown Source)
    <br> at oracle.cabo.servlet.PageBrokerHandler.handleRequest(Unknown Source)
    <br> at oracle.apps.oam.servlet.ui.OAMServlet.doGet(OAMServlet.java:215)
    <br> at oracle.apps.oam.servlet.ui.OAMServlet.doPost(OAMServlet.java:159)
    <br> at javax.servlet.http.HttpServlet.service(HttpServlet.java:521)
    <br> at javax.servlet.http.HttpServlet.service(HttpServlet.java:588)
    <br> at org.apache.jserv.JServConnection.processRequest(JServConnection.java:456)
    <br> at org.apache.jserv.JServConnection.run(JServConnection.java:294)
    <br> at java.lang.Thread.run(Thread.java:479)
    <br> </blockquote>
    (ERROR) an error returned handling request via protocol "ajpv12"
    (INFO) balance: continuing to ora-apps.world:16000
    (ERROR) balance: 852 internal servlet error in server ora-apps.world:16000
    (ERROR) an error returned handling request via protocol "balance"
    Any ideas on this problem. Any help would be greatly appreciated.
    Thanks!

    Thanks for your reply Mylenium.
    OK, now I can log into my Adobe (website) account and see my purchases, serial numbers, etc. .... AND ..... I am now able to log into my Applications Manager!!
    I did not do anything different from the other past few days; didn't load or download any software, nothing. Strange, but I'm glad it's back to normal now.
    Figures; when I go and seek out assistance ... it fixes itself.
    Thanks again ... and I hope this does not re-occur!!

  • I can't log in to course manager anymore. It says "error occurred"

    Hello,
    I wanted to log in to Itunes U course Manager and since yesterday
    I've noticed that I can't log in anymore. It's certainly not an Apple ID
    or password error. It tries to log in en then I get :
    An error occurred - try again.
    Does anyone know how I could fix this?
    Thank you
    François

    Hey Ximenalp,
    Thanks for the question. The following resource outlines the error message you are receiving, along with a potential resolution:
    iTunes: Advanced iTunes Store troubleshooting
    http://support.apple.com/kb/TS3297
    "Error -50," "-5000," "8003," "8008," or "-42023"
    These alerts occur due to timeouts or conflicts trying to write a file during download.
    If you encounter this issue while accessing iTunes Store:
    See iTunes 9: "One Moment Please" or "Error (-50)" message when accessing iTunes Store
    Thanks,
    Matt M.

  • Profile manager shows 'new device' instead of device name.

    Have just enrolled an iphone into profile manager for - oddly it just isnt showing up as it's proper name and attempts to 'update info' just hang. Our other deivces continue just fine. I can't figure out why this iphone is such a problem. I've restored back to factory iOS in tunes and its still just showign as 'new device'.
    Anyone else seen this?
    OS X 10.8.2, Server App 2.1.1

    I'm having the same issue now with a device that's on the latest iOS (6.1.1)
    Symptom:
    1.  Enroll device, no issue
    2.  Install Trust Profile and Settings for Everyone, no issue
    3.  Put user in proper Device Group, those settings never push down. Always show "sending".
    Troubleshooting:
    1.  Completed wiped iPhone and manually installed new OS - same issue
    2.  Removed user's account from our Apple Server, recreated account, reenrolled device - same issue.
    3.  Replaced the iPhone hardware - same issue
    4.  We have tried these steps both on the cellular data connection and on a unrestricted wifi connection - same issue
    Woudl really like to get this resolved.  Any thoughts would be appreciated.

  • User created but can't log into Portal. OID not in-sync with Repository.

    Logged into Portal as portal
    Go to Administ Tab
    Created a group i.e. TestGroup
    Created a user i.e. TestUser, put the user's default group as TestGroup.
    I logged-out and and tried to log in as TestUser it doesn't let me log into Portal.
    I do see the TestUser under TestGroup when going to Administer Tab and checking it, but some how can't log-in. I tried to use wwsec_api.user_in_groups to print the group names using SQL-Navigator but it never returns anything for the user I created above.
    username := 'TestUser';
    groupid := WWSEC_API.USER_IN_GROUPS(p_user_name=>username);
    ..........Now if if try the following and use portal it returns me all the groups the portal user is in i.e.
    username := 'portal';
    groupid := WWSEC_API.USER_IN_GROUPS(p_user_name=>username);
    ..........Looks like OID and repository are not in-sync. Can someone give some in-sight why is this happening and what can I do to fix this. I even tried adding the user under some other groups but still never returns me the groups when I run the above PL/SQL.
    Thanks

    Under Administer -> SSO/OID Tab I have Enable directory synchronization is checked. But still can't log in. Any ideas.
    Thanks

  • Profile Manager- url on device not working

    I have everything set up to use Profile Manager but when I access the url https://myhost/mydevices from my device on the first time it prompts me with an alert saying that the Identity on the Serer cannot be identified (as shown on the picture), I click continue, and after that it just gives me Service Temporarily Unavailable . Does anybody knows what I am doing wrong?

    (bump) Anyone?

  • Profile Manager: Service has failed with status 500?

    I am getting a "Service has failed with status 500" error when trying to enroll a device with profile manager. Does anyone have a resolution for this?

    In OS X Server 2.1.1 there seems to be an error, according to: https://discussions.apple.com/thread/4365626?start=0&tstart=0

  • Can't log in message "what is the username associated with this smartphone​"

    When I attempt to login to app world, I enter my email address and pw, and the it gives me a popup for - "what is the username associated with this smartphone".  How do I find out what to enter here?  (I don't remember what I may have used in the past).  
    Also, how can I be sure that I am using the right email address to login?  I've tried my other emails and I get stopped before this screen since it doesn't recognize the email.
    THanks for your help

    How can you do a security wipe if you cannot get past the blue BlackBerry ID login page?

  • Managed users with Active Directory?

    Hi guys
    I was wondering if any of you can help me out. I'm looking to get a OS X Server 10.4 to act as a managed user server, with all the pros of Open Directory (ie Finder restrictions etc) and user home directories on the Xserve's HD, but to authenticate through a Windows 2003 Active Directory Server.
    I have been reading a number of sites and there seams to be two ways to do it.
    1) Bind the Xserve and the client Macs to the Active Directory and then on the PC server specify the home folders as a share point on the Xserve. Ie \\Xserve\Users\Tom
    This way the Xserve is basically a file server.
    2) And I'm cutting this story short because I've only briefly read this one. But you can set the Xserve as an Open Directory master, some how import the users and then remove the directory master roll.
    I really need to be able to have the usernames and passwords live from the Windows Server due to passwords being changed every 30 days blah blah blah so I guess point 2 is out of the question.
    To be honest a yay or nay to the above would be a good start, could obviously save a lot of wasted time, but if anyone can recommend me a website or a pdf that will walk me through it.
    I've managed to get my laptop to authenticate to AD but cant get the home directories to work. Every time I log in with a user account it creates it locally on my HD. I do not have "Force local home directory" checked. I guess I need to configure LDAP to the AD server as well? I gave it a go an managed to get Address Book pulling users and emails from the AD sever. I then preformed a lookupd lookup on a user bob and found that the home directory was set to /Users/bob even though on my AD server I've set it to \\Xserve\Users\bob is this something I'm doing wrong with LDAP? If thats all it is I'll be able to get point 1 above working and it will all be good.
    I hope I've made this clear enough for someone to be able to help me.
    Thanks in advance for any help you might be able to give me.
    Tom
    1.25GHz PowerBook G4   Mac OS X (10.4.4)  

    With an OD master you could manage your clients at the group and computer list level.
    So when you setup the user's profile in AD, you mapped a network drive and provided the UNC path \\Xserver\Users\bob. You did bind the OD Master with the name Xserve? Also, by default it will use smb to connect, which you can change to afp instead in the AD plugin. smb will not create the home folder for you. You could try to create the home folder yourself in advance. (sudo createhomedir -a may do the trick)
    For troubleshooting purposes, you could create a share on the AD server and adjust the user's profile to point to it instead of the OD Master. Try and login and see what you get.

Maybe you are looking for

  • Photobooth only shows a black screen

    I have a friend with a new core duo, his photobooth was working fine and then stopped showing only a black screen. It will snap a photo but the photo is black. The camera works fine in ichat. I deleted photobooth and reinstalled from the install DVD

  • [JS, CS3] Change text color and export pdfs

    Hi there, I am new to scripting and I am trying to find out if a script exists that will export a PDF, then change all text of a certain color to black, then export another pdf with the same settings as the first, but appending the filename. I've sea

  • A question about photo storage.

    In several cases photos in my Library are used in multiple albums and slideshows. This has the effect of having them show up multiple times in the Library. My question is, are there actually multiple instances of these Photos (because some of them ar

  • Accessing Yahoo Busines Mail Options

    I have just been through a couple of months of **** with Yahoo! Business Mail. I haven't been able to get emails from any of my friends/clients who had a gmail account. Yahoo!'s tech told me that gmail.com was blocked, and s/he claimed s/he unblocked

  • Java - XML mapping

    I want to generate/map a xml schema from a set of java classes (like JAXB or XMLBeans). This not for a web service implementation. Is there any I can use the autotype ant task available in weblogic webservice to achieve this ? Thanks, Siva