How to Move Local Users to Network Domain Users

Before you follow these instructions...... I'm a rank amateur so I'd check to see if the smart kids have corrected my errors or improved on the method in the replies below
The reason for the post is I have good and established local user accounts on all the computers and moving them to domain controlled accounts is the one topic I could not find a script to follow that worked for my low level of knowledge of OS X.
Let me first explain my setup and needs. I'm replacing a Windows Home Server (WHS) with the Mac Mini Server. My goal was to have the Mac Mini as the server holding all our photos, data, etc. and running a user account to run the family iTunes account to feed the Apple TV and be the backup / sync point for a family sized set of iPod Touches, iPads and iPhones. I want to be able to log into each mac and have the same information setting, links, etc........ basically walk around the house, find any mac shaped device not used by someone else, log in and carry on where I was before -  with the MacBook Air having a portable account so it can come travelling with us.
The key hardware is...
Mac Mini Server running Snow Leopard 10.6.8
Apple TV
2 x iMac Running Lion 10.7.1 [upgraded from 10.6.8]
MacBook Air running Lion 10.7.1 [upgraded from 10.6.8]
Normal stuff like wifi, hubs and a router doing the DHCP (and for me reserving IP addresses based on the 'MAC Address' to save me having to manually configure all the IP addresses)
Key Resources I used as I learnt how to do this; to level set you all, I'm a relative newcomer to OS X having had a Windows life with Linux for fun, so i'm not a mac or IT specialist but like to play around.
Apple's podcast series 'Apple Quick Tour of Leopard Server'  - this is great, it informed me and kept me motivated through all the bah moments, all 33 episodes and it's in the iTunes store as a podcast.
The book 'Mac OS X Snow Leopard Server For Dummies' - I bought this about half way through the whole process and wish i'd bought it earlier, my reccomendation would be get the Kindle version so you can search it for advice.
The excellent information on DNS from Hoffman Labs http://labs.hoffmanlabs.com/node/1436
The video 'Setting up a primary DNS zone.....' from Lynda.com on youtube  http://www.youtube.com/watch?v=OOEgQY9oFK4
The Series of PDF document on Snow Leopard Server from Apple http://support.apple.com/manuals#mac%20os%20x%20server%20v10.6
And finally this excellent post from Joe Ferrante which was the core of what I used http://joeferrante.net/how-to-migrate-local-user-account-to-network-user-account -with-networked-home-folder-on-snow-leopard-server/
Right off we go....
Setting up the Server [this took me 6 goes to get it right as I learnt a little each time].
So i'm not going to go through this step by step because it in the 'dummies' book and the videos from Apple above and those will be better than anything I write but here's my details/advice.
I split the primary disc into 2 partitions using disk utility so I could reformat the operating system without moving my data.
100GB for the OS X system
400GB for user data
Install OS X from the DVD, press the buttons based on your desires but stop at the bit about naming you computer titled Network Names
READ UP ON DNS  - this one of the reason I had so many goes as it was the 1st time i've set up a server like this using DNS and guessing didn't get me there.
If you don't have one buy a domain name for your network it make it much easier in the long run & is $10 well spent
The name needs to be [the computer name].[your domain name].[com or net or org, etc]
So if you want you computer to be called fred and you bought or have the domain location.com enter fred.location.com in the primary DNS name box
This shoud automatically put fred in the computer name box.
Follow along with the set up guide to finish
After you have finished the set up test the DNS with NSLOOKUP in a terminal window
nslookup fred.location.com    in my example and you should get the IP
Add your servers IP address to the list of DNS servers in network preferences on the client mac.
Bind [link] the client computers to the server in Accounts on the client computer - I used the 'dummies' book for this but there's lots of data on the web.
Clean up the user profile on the client to reduce the size of the Home folder as much as possible or the data transfer is loooooooonnnnng - i also connect the iMac on a cable rather than wifi to speed it up.
Read Joe's post http://joeferrante.net/how-to-migrate-local-user-account-to-network-user-account -with-networked-home-folder-on-snow-leopard-server/ and follow along.useful info I learnt somewhere - to get the paths to the folders correct in the terminal window go to the folder in Finder and then drag it to the terminal window and let go - this will put the correct link in the instruction.
You now need to be on a terminal window on your server, with a finder window open and logged into the client as the user you are moving
THE CLIENT COMPUTER NEEDS TO BE LOGGED OUT or logged in as a different user than the one you're trying to move.
so when you're at the right point - type sudo cp -R then hit the space bar, drag the existing user folder onto the finder window, add the /* and hit space then find the users folder on the server and drag that onto the terminal window to complete the instruction.
Hit enter and wait a while assuming it starts ok - i used network traffic on the Activity Monitor utility to check if it was working.
If you got this far and it all worked - login to the profle you moved on any computer linked to the server or the server but not the original client computer to see if it worked and all your setting and data are intact and then delete the profile off the original client if it was ok [archiving the home directory took ages for me].
As you can probably guess most of this was good learning for me and it worked successfully for me in the end, moving all my history, saved password, etc, etc without any problems.
Hope this helps other in the same situation & feel free to expand or correct this if I've missed anything.
Ed

Hi,
I was unable to access the Joe Ferrante information (it appears to now requrie a password and was not able to determine how a username and password were assigned)  Would you happen to have a copy of the post that you refer to above?
I am still at the early stages of this process but am hoping that the steps you refer to are going to get me where I want to be.  Your stated end goal is where I hope to get to.
Thanks,
Sean

Similar Messages

  • Help! How to migrate local account settings to domain account in Windows 8.1 Pro

    All kinds of answers to this question come up for Windows 7 (even though I specify Windows 8.1 Pro)
    Anyway, have a laptop originally with Win 8.1 and a local account created.   Upgraded to Win 8.1 Pro and logged in as domain user.  How can I copy all the settings I had as a local account to my domain account? Surely SOMEONE has found a way
    to do this?

    Hi,
    You can use USMT to achive your goals. However, I doubt whether you would encounter some problem, as domain controller would set some restricted settings and some policy of your local account won't be applied.
    To know more about USMT, please refer to the link below:
    http://blogs.technet.com/b/nepapfe/archive/2013/04/15/using-usmt-v-5-to-migrate-your-profile-data-apps-amp-profile-settings.aspx
    Roger Lu
    TechNet Community Support

  • How-to move objects (users) from one ou to another using Powershell and an XLSX

    Hi all,
    I have a spreadsheet that has headers. I need to move all of the objects on this exception report to the proper OU (all going to the same OU).
    The header that validates the need to move is called "Display Name".
    The process now is as follows.
    1) Copy displayname
    2) Open AD search
    3) enter display name in find box
    4) locate object
    5) right click object in results and click move.
    6) move to the OU "Home.test.com/uk Online/Users OU/Business Process"
    --- How can i use Import-CSV to automate this process?
    Thanks for any help, there is about 4K lines on this sheet and it normally takes about 25 days of "busy work" to accomplish this, then 5 days later I have to re-run the report and start over.
    Josh
    Josh Borges

    Hi Josh,
    This assumes that you can save your file as an actual CSV file:
    $skippedUsers = @()
    Import-Csv .\userList.csv | ForEach {
    $displayName = $_."Display Name"
    $user = Get-ADUser -Filter "DisplayName -eq '$displayName'" -Properties DisplayName
    If ($user.Count) {
    $skippedUsers += $displayName
    Else {
    $user | Move-ADObject -TargetPath 'OU=Business Process,OU=Users OU,OU=uk Online,DC=home,DC=test,DC=com' -WhatIf
    If ($skippedUsers) { Write-Host 'The following users could not be moved automatically:' -ForegroundColor Red ; $skippedUsers }
    Do you have to use the display name property? That's not guaranteed to be unique, so you might run into problems. The script above will not attempt to move the user if more than one is returned by the command.
    EDIT: I've also added -WhatIf to Move-ADObject. Now the command won't actually move your users, it will just tell you about it. Remove it if you're happy with the output.
    Don't retire TechNet! -
    (Don't give up yet - 12,420+ strong and growing)

  • HOW TO CREATE LOCAL USER PROFILE

    SIR,
       OS            -    WINDOWS SERVER 2008 R2
       SYSTEM    -    IBM  MACHINE X3400 SERIES
        1. HOW TO CREATE A USER IN WINDOWS SERVER 2008 R2  WITHOUT ACTIVE DIRECTORY 
        2.  AFTER CREATE USER IN WINDOWS SERVER 2008 R2 BUT USER PROFILE NOT CREATE .

    Hi,
    >>1. HOW TO CREATE A USER IN WINDOWS SERVER 2008 R2  WITHOUT ACTIVE DIRECTORY 
    >>2.  AFTER CREATE USER IN WINDOWS SERVER 2008 R2 BUT USER PROFILE NOT CREATE
    Creating an user account on the computer doesn't create a profile for that user. The profile is created the first time the user interactively logs on at the computer. After the user logs onto the computer for the first time, the user's local profile
    will be created in a folder with the name of the user under the systemroot/Users folder.
    Best regards,
    Frank Shen

  • How to move my user account to new SSD?

    I just received my new mid-2011 27" iMac with the 1TB HDD and the 256GB SSD.  It came from the factory with the /Users directory on the SSD, which is not a good idea (at least for me) due to the size of my iTunes library, movies, documents and other stuff.  Can I move /User/"myUserAccount" from /Volumes/Macintosh HD to /Volumes/Macintosh HD 2 (as the HD is named)?  Surely this is possible, but I don't know the correct way to do this.  Any help would be appreciated.  And if anyone has general advice on how to properly use the SSD I would appreciate that too. (Stuff like what to put where, etc.)
    Thanks!

    Leave your user account's alone!!!!!! All you need to move are the data files. What takes up a lot of space is music, photos & movies. If you move those libraries to your internal HD that will take care of things for you. Here are Apples instructions for moving them to external HD's however you can use your internal HD the same way.
    iTunes: library on EHD
    iPhoto: How to move the Library to EHD
    Roger

  • How to handle local user in SSO?

    Hi all,
    I'm setting up OAM 11g for SSO of web applications in our organization.   Some of the applications have single URL for both corporate users, guest, and administrators.  As the OAM is using corporate LDAP as authentication backend, guest and administrator can't be authenticated.  Is it possible to define policy so that a webgate protected URL can fallback to original login page?   I'm newbie to OAM and sorry for the newbie question.  Thanks.
    Regards,
    /ST Wong

    I think you misunderstood. The local users won't be added to the backend LDAP but in a local store on OVD. OVD then makes it appear that that user is in the backend LDAP if you want it to appear in the same tree structure, or you can place the users in a completely separate tree. This of course assumes that your user base search in OAM is set to the top level.

  • How Make TS local User Profile After Install Windows 7 without Domain

    Hi,
    I make TS to install Windows 7 Is success But after finish install i cannot login
    If something need to add TS user local profile after install Windows 7 Without Join the Domain And make the user Administrator LocalGroup
    Thank for Help

    Let's start with the fact that you are missing a key element in your task sequence. You need to have the step
    Setup Windows and ConfigMgr to perform the transition from Windows PE to the new operating system. This task sequence step is a required part of any operating system deployment. It installs the Configuration Manager client into the new operating
    system and prepares for the task sequence to continue execution in the new operating system. See also for more information:
    http://technet.microsoft.com/en-us/library/hh846237.aspx#BKMK_SetupWindowsandConfigMgr
    About your screenshots:
    With the first screenshot you not enabling the local administrator. Is that what you want?
    With the second screenshot your only creating a user account and not adding it to the local administrators group. That would need an additional action like this
    cmd.exe /c net localgroup /add administrators User01.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • How to manage local user home folders?

    We are using Mac OS X 10.6.8 in a classroom. Hard drive has two partitions, one for OS and apps, the other for student's files. Computers are bind to the Active Directory. Unfortunately, local home folders are on the boot parition. Over a time when apps FCP and Avid are frequently used, the boot partition gets filled with files and finally it's full. With zero kb available, users cannot even login anymore. Manually deleting files by admin is cumbersome and time-consuming task.
    I'm looking for a way to keep /Users folder clean. Putting user's home folders to server is not an option, because of latency issues etc. Unfortunately the local home folder is the default saving place when user issues the Save As command. I've tried to tinker with the User Template to lock the Documents folder but apps like Microsoft Word and Final Cut Pro go crazy when they cannot save there.
    Forwarding /Users to other partition does not solve the problem, it just moves the problem to another place.
    Logout Hook to automatically purging the files could be an solution, but there's always one hapless soul who saves his or hers files to wrong place and loses them. Or maybe a script which looks at the modfication date and deletes old files.
    Any ideas?

    You need to set the scratch disks in FCP and Avid to fix the problem.
    Files coming from word etc, will be so minor that it'll take forever to fill up the HD with that kind of stuff.
    If you wanted to move the whole home folder to another place on the system, you need to do so using OS X server.  It's called Augmenting Active Directory User Records.
    If you don't have an OS X Server, you may be able to change the Users Home directory on each individual computer, but it's going to be pretty cumbersome.  Do so in the Accounts pane in the System Preferences.
    Once you've changed the User Home folder location, you need to copy the users home folder using rsync in the terminal.
    Like this:
    rsync -av /Users/*username* /Volumes/*drivename*/*homefolderlocation*/
    HTH
    -Graham

  • How to move local Adobe folder?

    Hi folks -
    I have a small Intell SSD for my O.S.(Win 7 64 bit) which is blazing fast. Unfortunately, Lightroom keeps sending huge files to:
    C:\Users\***\AppData\Local\Adobe
    Is there a way I can move this folder to my data drive so I don't have to keep deleting it?
    Also, where can I find the "paste" option in this post box? That would have saved some time.

    Mikewolv wrote:
    Hi folks -
    I have a small Intell SSD for my O.S.(Win 7 64 bit) which is blazing fast. Unfortunately, Lightroom keeps sending huge files to:
    C:\Users\***\AppData\Local\Adobe
    Is there a way I can move this folder to my data drive so I don't have to keep deleting it?
    Also, where can I find the "paste" option in this post box? That would have saved some time.
    What files are they?
    Beat
    P.S: Paste can be done by right-clicking ...

  • How to move iWeb site with missing Domain.sites file

    I've been asked to host a friend's iWeb site now that MobileMe is no longer an option.  The problem is that the MacBook it was created with is long gone and the only original files remaining are the image files for the site. No Domain.sites file.  They are also not sure which version of iWeb was used, if that even matters.  Initially I was thinking we could just access the existing site using ftp and go from there - upload the site to my hosting account and use Dreamweaver to maintain it, but everything I've read seems to point to 'Not gonna happen that way'.
    Is there a way to transfer an existing iWeb site hosted on MobileMe to a new hosting account and be able to work on it with another editor, all the while not having the original Domain.sites(2) file?
    Thanks much,
    Mark

    Quite a few people are moving to other drag and drop style editors like Sandvox and RapidWeaver although they aren't really any better - just more expensive.
    I advise people not to use iWeb for new sites and just to keep it going to update existing ones until they are defunct or rebuilt some other way.
    I quit using iWeb about a year ago due to the fact that it, and similar apps, can't create responsive designs for mobile devices although I did figure out a stop gap design for iPhones...
    http://www.iwebformusicians.com/iWeb/Mobile-iWeb.html

  • How to reset local admin user password in

    Dear members,
    i want to reset local admin account(not administrator built-in), let say i have user adminlocal and member in administrator group. my question, how to reset this user via GPO in domain, because i have more than 5000 workstation in my environment. and how to
    generate summary of all workstation which are password reset.
    i've tried from this link,
    http://community.spiceworks.com/how_to/show/1966-how-to-change-local-user-or-admin-passwords-on-remote-computers
    using PSTools sysinternal from microsoft, but while i execute one PC on domain for sample using this script, they showing access denied
    anyone in this forum can help me to resolve this problem?.

    Dear,
    you can use Powershell to do this.
    I've found a script in the script center which can do this.
    http://gallery.technet.microsoft.com/scriptcenter/66a5b38f-cdf1-4126-aa0c-be65e16dd650/view/Discussions#content
    Set-Password -computer 'server' -user 'Administratorlocal' 
    You can create a loop in powershell to check all your servers which you've posted in a .txt file for example.
    $strcomputers = Get-Content c:\servers.txt
    foreach ($strcomputer in $strcomputers)
    $admin=[adsi]("WinNT://" + $strComputer + "/administratorlocal, user")
    $admin.psbase.invoke("SetPassword", "Whatever1")

  • Best way to migrate local users to the network - move home folders?

    Hi everyone,
    I am about to set up my Mac mini server (Snow Leopard Server). I have one iMac with three user account on it (local), another iMac that we just bought and my MacBook Pro with my admin account on it (Snow Leopard). So all have Snow Leopard.
    What would be the best way to move the three local accounts AND their home folders to the server?
    What would be the best way to make my portable user account into a mobile user account on the server?
    I am planning to create all users on the server (with the same username and passwords etc.) then move the local home folders from the iMac to the server through some direct wired connection. My concern is with this move - will there be permissions mismatch issue? I am sure there will be as the UID would be different for the same accounts (pre-existing and newly created, eventhough their username and passwords are the same).
    Any best practices? strategies?
    Does Apple have any documentation on this specific topic? - that is moving local user accounts and their corresponding home folders onto the server?
    Thanks much!
    Kenneth

    Hi again,
    I haven't gotten round to it - but may have an alternative route in the mean time: the brand new 27" iMac just arrived, and rather than doing a full 'migration assistant' setup, I am going to try the following:
    1. on the new iMac: only create a local Admin account, user name totally unrelated with any other account name;
    2. on the server: settle all the network user account settings, portable home directories, managed preferences etc. for each user;
    3. on another computer: log on under the corresponding local user account, and copy one's home folder entirely to an external drive - do not use this machine again under this user account;
    4. on the new iMac: log in as a network user, make sure the home folder and library syncing works as desired, set some preferences (and check that this gets synced to the server drive); copy the parts of the home folder & library for this user from the external drive - wait until it all gets synced back and forth - and check any permissions, preferences whatever issue (the local account on the other computer is available for cross-checking, just don't change any documents or settings on that one)
    5. if all works well on the new iMac: delete this local user account on the other computer.
    6. repeat steps 3-5 for each other computer where this user has a local account (one 'old' iMac, one 13" MB) - will also allow to check and filter any duplicate documents which have accumulated over the different machines.
    7. create the network accounts for this user on the other computers, and check the syncing etc.
    8. repeat for each user (4 in total for us).
    I think this might just work, since the new iMac at present has no accounts - so no possible issues with similar account names & passwords etc - and you keep the 'old' local account on the other machine as a safeguard anyway.
    Any particular thoughts or comments on this proposed process??
    How about permissions: does the copying to an external disk, and then back onto another computers disk solve that??

  • How to know RAC 11g R2 is installed Using Local User or Domain User on Win

    We need to identify whether a local User or a domain User is Used to install 11g R2 Clusterware on Windows 2008.
    Here is background:
    Oracle 11g R2 RAC is configured on 2 windows 2008 servers.
    User "oracle" is used to installed that RAC but we dont know whether local "oracle" user or domain "oracle" user is used to install this RAC.
    "oracle" user is present in both the servers as a local user as well as a domain user.
    Due to security reasons we need to remove this local "oracle" user but without knowing which user is installation user for rac we cant remove as this will disturb whole rac setup.
    Please sugest me some solution ......

    Right click on any folder from oracle home -> Security (tab) -> Advance -> Owner.
    This will show you who owns this folder and that should be the user who did this installation. You may see 2 users where, one will be local administrator and second one will be the user who did installation.
    Salman

  • How to move all files from a folder for a user to a centralized folder on a core server with a GP

    Hello,
    I was curious if someone know how to move all the files of a user "local" profile on a Terminal Server to that of a centralized server where the "local" profile of like the user desktop, favorites, setting, etc are stored in the event
    the local profile on the TS become corrupt it can pull from this server...
    The problem I have is no matter what I tell users to save there files to our Y drive that is a folder that is synced
    across all 6 of our TS servers, users still store files on there desktops, so as you can imagine if one day they are on one server, then next day they could be on another and there files aren't the same.... hence the reason why I want to move all there files
    to the centralized server so when I redo the profiles from scratch on the TS server in the farm they suck files from the core server and have all of the files they are used to having.... 
    So I was curious and I've heard from some this is possible in a GP, but I'd like to move the contents of all 6 TS for
    each user or if I have to d this on  per user basis I will, just looking for a way to move the files....

    Hi Trevor,
    To move all users’ desktop to a server, we can use Folder Redirection to do this. The path for Folder Redirection is:
    [Group Policy Object Name]\User Configuration\Policies\Windows Settings\Folder Redirection
    In this situation, we can choose to redirect desktop to the root of a network file share or a folder on a network share.
    Regarding how to configure this, the following article can be referred to for more information.
    Configuring Folder Redirection
    http://technet.microsoft.com/library/cc786749.aspx
    Hope it helps.
    Best regards,
    Frank Shen

  • UAC - Standalone local user vs domain user

    Hi,
    I have an application that during first launch runs a regedit /s command to import some registry keys into the user's (HKCU) registry.
    I have discovered if I run the application logged in as a local user (No admin privileges) with a machine that is not joined to the domain, I can launch the application. I can also launch regedit manually with no UAC prompt.
    However if I join the machine to the domain and log in as a domain user (No admin privileges) then the application fails to launch due to a UAC prompt at the regedit /s stage and also trying to open regedit also results in a UAC prompt. Using the standalone
    local user on a domain joined PC also causes the UAC prompt to appear for both the application and directly launching regedit.
    Is this by design - as in the joining of a PC to the domain changes how UAC works? As a test I have moved both the user and computer in AD to a test GPO which has no GPO's applied except the Default Domain policies which have no UAC settings in them?

    Local group policy take precedence over domain.
    Group Policy processing and precedence
    http://technet.microsoft.com/en-us/library/cc785665(v=ws.10).aspx
    Previously your uac prompt was not there, may be because you have disabled uac? Or did you run it logged under local admin/built in admin? 
    If uac is not disabled/altered uac prompt should be prompted for all the users except built in administrator.
    http://windows.microsoft.com/en-us/windows/what-is-user-account-control#1TC=windows-7
    Hetti Arachchige V Aravinda | Network & System Administrator (B.Sc, Microsoft Small Business Specialist, MCP, MCTS, MCSA, MCSE,MCITP, CCNA, CEH, MBCS)

Maybe you are looking for