Macbook bound to AD won't allow network login or new local account creation

As the title states I am having an issue related to a macbook pro that is bound to active directory. The only option we tweak when binding the macs to AD is that we opt to "create mobile account" option under directory utility.
It also seems that while we can login through the local admin account, new local accounts cannot be created (the account creation window hangs when you create account).
Any help would be appreciated

Hi
To successfully bind a mac workstation to Active Directory certain things need to be in place:
DNS has to be fully resolving on both pointers. This is done on the PDC or whatever server is the designated DNS Server.
Date and Time settings need to be adjusted to reflect whatever is designated as the NTP Server in the AD environment. Adjust the Date & Time Preferences Pane and find out from the Windows Network Administrator what the NTP Server IP address is.
You must use account credentials that has authority for the AD Domain. If you're trying to use your own account it may be restricted in what it can do? A domain account has special privileges not usually accorded to ordinary user accounts.
This assumes you're (a) not the Active Directory Network Administrator and (b) you're using the Active Directory plug-in the login options section of the Accounts Preferences Pane. It's a good idea to click the "Open Directory Utility" button when binding to Active Directory. It's also a good idea to access the Advanced Section once the Utility has opened.
If this is failing at the bind stage then perhaps you should review the details you've been given when binding to AD? It may be worthwhile to clear the workstation from the Computer OU before you try again?
The above is not an exhaustive list but should help?
Tony

Similar Messages

  • I bought a second hand MacBook Air and it won't allow me to install updates as up pops the previous owners log in details. How do I go about amending this?

    I bought a second hand MacBook Air and it won't allow me to install updates as up pops the previous owners log in details. How do I go about amending this?

    The seller was remiss in not properly preparing the Mac for sale. That task has now fallen to you. You will encounter continual problems until you perform the following. Ignore references to DVD since the MacBook Air has none.
    If you are unable to do that contact the seller and request instructions, or arrange for its return and a refund of your costs.
    Refer to What to do before selling or giving away your Mac
    If you enabled FileVault, disable it in System Preferences > Security & Privacy.
    "Deauthorize" your iTunes account. Same for Audible if you have one.
    System Preferences > iCloud > de-select "Back to My Mac" and "Find my Mac".
    Sign out of iCloud. Select "Delete from Mac" when it appears.
    Next: Remove all your personal information by completely erasing the Mac's internal storage.
    If your Mac shipped with a grey System Install DVD, start your Mac with that disc inserted in the optical drive while holding the c key to boot from it instead of its internal volume, which should be erased before selling it.
    If your Mac did not ship with discs, boot OS X Internet Recovery:
    using three fingers press and hold the following keys: ⌘(command), option, and R.
    With a fourth finger press the power button to turn on the Mac.
    Keep the other three fingers where they are until you see the "spinning globe" icon.
    This method forces the Mac to download its originally installed OS from Apple's servers, which will not require an Apple ID to install.
    Remove any Open Firmware password if you created one: select Firmware Password Utility from the Utilities menu and remove it.
    Select Disk Utility from the Utilities menu.
    Remove any partitions you may have created.
    Select the Mac's hard disk icon, then select the "Erase" tab.
    Select the "Security Options" button and erase the disk.
    The more "securely" you erase the disk, the longer it will take.
    The fastest method is sufficient since all but the most expensive techniques and equipment will be able to recover securely erased data.
    When it finishes, quit Disk Utility.
    Select Install Mac OS X from the Utilities menu.
    An Apple ID will not be required. If a prompt for an Apple ID appears, return to Step 5.
    Do not create any user accounts.
    When it finishes, shut down the computer.
    If you want to install the bundled apps that were included with your Mac, restart by using your Applications DVD if one was included, and install the bundled apps. Apps bundled with newer Macs that shipped without discs cannot be transferred. Its new owner must purchase them from the Mac App Store using his or her own Apple ID.
    If the Mac is being sold to someone outside the family consider the following additional information:
    System Install DVDs that came with your Mac should remain with it forever, and must be included with the sale.
    Consider including your AppleCare certificate if you bought it, printed documentation, even the box if you still have it. AppleCare stays with the equipment and is transferable.
    Execute a bill of sale showing the Mac's serial number.
    Once no longer in your possession, remove the Mac from your devices in My Support Profile.

  • Dvd/cd drive works but won't allow me to install new programs from disk, doesn't recognize the disk,

    dvd/cd drive works but won't allow me to install new programs from disk, doesn't recognize the disk, what can I do?

    Well I was able to obtain a work around download of Flash and it installed fine but Firefox tells me it needs updating so I go out, thinking I'm "IN" finally to update it and I get that issue of not being able to get the update for it.  It's a regular laptop, not a touch screen or one of those new fangled ones for todays world.  In fact it's a refurb so it's probably origin date was a year or so ago before all this MS stuff took off fully.  So not understanding why I'm feeling like I'm being BLOCKED from getting the updated Flash I need and desire.  If I click on the little "X" and tell it to ignore the warning the vid will play just fine but don't want to have to do that every time.  Must be a better way. 
    Again, I'm sorry for posting in the wrong forum, getting this posted in the Flash forum was my desire but the way Adobe has this set up I just couldn't figure it out.  I belong to ALLOT of forums and most are pretty straight forward but this one is confusing! 

  • Won't allow me to open new tabs

    Firefox won't allow me to open new tabs anymore. When I click on the "open new tab" icon, nothing happens. How can I restore this feature to normal operation?

    Uninstall the Ask toolbar add-on. It has a known compatibility issue with Firefox. See this article on the uninstallation steps: [[Uninstalling add-ons]].

  • Can only "Save to online account"  when I try to "save as" won't allow me to save to local disk.

    Can only "Save to online account"  when I try to "save as" won't allow me to save to local disk.  How do I "save as " to local disk like I always used to?

    Open a PDF. Cry ah-ha!
    Select one of Acrobta's Content Editing tools. The save icon becomes active. Cry ah-ha!
    Selection of / use of other tools can result in the save icon becoming active.
    Try each in turn (do remember to have a PDF open).
    Cry with delight at each Ah-Ha moment. 
    Be well...

  • Restricting allowed network logins

    I'm hoping to find a way to restrict newtork logins.
    I have an environment with both openldap on linux, and Active Directory directories available to authenticate against. These directories are synced, so it doesn't matter which directory service is used.
    I have successfully authenticated using network logins with both of these directories.
    My problem is that I have a group of semi-public computers, and I would like to limit the allowed network logins to a small list of users, rather than the whole directory.
    On linux, I was able to do this with a hodgepodge of pam_ldap configurations, allowing login only if there was a local home directory. So I could manually add a user locally with their netowrk uid, but they would use thier network password.
    Is there a method to do this with OS X? To restrict allowed network logins to a list of uids?

    I tried the osascript line and killall -HUP loginwindow in a loginHook script without success.
    If I run the loginHook script from the terminal..
    "sudo /Library/Management/get-user-info.sh nghani"
    it works fine but when I login as nghani..
    no osascript and
    no restricted login
    From the debug file I know my script is running from the LoginHook and the logic is correct.
    Am I missing something?
    Please help!!!!
    /Library/Management/debug:
    nghani is not ics or root
    nghani user is not in group
    button returned:OK
    kill -HUP 600
    nghani is not ics or root
    nghani user is not in group
    root is ics or root
    /Library/Management/get-user-info.sh:
    #!/bin/sh
    shortname=$1
    if [ "${shortname}" = "ics" -o "${shortname}" = "root" ]
    then
    # local admin accounts do nothing
    echo "${shortname} is ics or root" >> /Library/Management/debug
    exit
    else
    echo "${shortname} is not ics or root" >> /Library/Management/debug
    # do ldap search to get email addresses + fullname + groups
    ldapsearch -H ldaps://ldapnw1.instruct.langara.bc.ca -D "cn=MacProxy,ou=ProxyUsers,o=Aves" -w `cat MacProxyPassword` -b "ou=Users,o=Aves" -s sub -x cn=${shortname} cn mail fullname groupMembership > /Library/Management/Thunderbird/user-info
    # UGLabsAll
    if [ -n "`cat /Library/Management/Thunderbird/user-info | grep groupMembership: | grep -e 'UGLabsMac'`" ]
    then
    # user is a member of the required group.
    echo "${shortname} user is in group" >> /Library/Management/debug
    else
    # user is not in the right group LOGOUT!
    echo "${shortname} user is not in group" >> /Library/Management/debug
    # tell user
    osascript -e 'tell application "SystemUIServer"' -e 'display dialog "You are not permitted to use this computer. You will now be logged out." buttons {"OK"} default button "OK"' -e 'end tell' >> /Library/Management/debug
    # logout
    /usr/bin/killall -v -HUP loginwindow 1>> /Library/Management/debug 2>> /Library/Management/debug
    fi
    fi
    G5 Tower 1.8GHz Mac OS X (10.4.4)

  • TS3988 On my Windows laptop I updated my Apple ID and changed my pw on my laptop. I forgot my old Apple account pw. My iPhone demands the old login info and won't allow me to delete the old account

    I need help managing my Apple account across my Windows laptop, iPhone 4s, and iPad iie. I updated and changed my id and pw because I changed email and forgot my old Apple pw.  Neither my iPhone or iPad recognize the updates.  Both demand the old account info and won't allow deletion of he old account on either device. Without the old id/pw combo, how do I access and update my Apple ID and iClount accounts for my iPhone and iPad?

    If the old ID is yours, and if your new ID was created by editing the details of this old ID (rather than being an entirely new ID), go to https://appleid.apple.com, click Manage my Apple ID and sign in with your current iCloud ID.  Click edit next to the primary email account, change it back to your old email address and save the change.  Then edit the name of the account to change it back to your old email address.  You can now use your current password to turn off Find My iDevice, even though it prompts you for the password for your old account ID. Then save any photo stream photos that you wish to keep to your camera roll.  When finished go to Settings>iCloud, tap Delete Account and choose Delete from My iDevice when prompted (your iCloud data will still be in iCloud).  Next, go back to https://appleid.apple.com and change your primary email address and iCloud ID name back to the way it was.  Now you can go to Settings>iCloud and sign in with your current iCloud ID and password.

  • Yosemite mail won't allow me to add a gmail account to it. Help?

    After downloading Yosemite, I changed the password to my school gmail account. Shortly after I realized that Mac Mail would not allow me to send or receive messages. I deleted the gmail account off of my mac mail, and tried to add it again later in order to circumvent the problem. It did not work, as I now cannot add my gmail account back on. Accounts immediately replies "Unable to verify account name or password", or "cannot discover the account settings for the mail server ---." Any advice??

    Hi njs72,
    Thanks for the question. Based on what you stated, it seems like you are not able to re add the email account to Mail. I would recommend that you read these articles, they may be helpful in troubleshooting your issue.
    OS X Mail: Troubleshooting sending and receiving email messages - Apple Support
    Mail settings you might need from your email provider - Apple Support
    Thanks for using Apple Support Communities.
    Cheers,
    Mario

  • RH10 won't allow me to create new topics with TFS

    Hi Everyone,
    Has anyone had a problem with TFS and RH10 where RH will not allow you to create a new topic?

    Haven't seen that before. Do you get an error or something?
    Do you know whether this is an issue stemming from TFS or could something in the RH project be broken? For example, if you make a copy of the project and unlink it from TFS, can you then add topics?
    Is is possible to import a topic into the project?

  • My iphone won't allow me to download new apps

    I have never had this issue before. It tells me I can retry. I am downloading apps directly on my phone. I was able to last night.
    It is not saying I need to reconnect to the internet but I am wondering if this is because of a bad internet connection or what?
    I updated my phone last night but was still able to download apps.
    And I have shut the phone on and back off so I am hoping someone can help.

    I am also having a problem similar to this. I can download apps from my computer and put the on my iphone 4 however when I try to download with the app store on my iphone it tells me that I need to use another method of payment and I am sure the informaiton entered is the same as on my computer. Can someone help?

  • Itunes won't allow me to drag new content into it (import it).

    This is all content types. Itunes would act like it was importing it but no content would show up in it's library. I have tried searching for the content in the itunes folder also but it was not imported.
    Now I don't even get a green plus circle when I drag the content, it just springs back to the folder i dragged it from.
    Does anyone know why this might be happening? It is happening with mp3s from multiple sources that are not copy protected and .avi movie files which are part of a collection that I have imported some of before.

    Kev303 wrote:
    It is happening with mp3s ...
    try verifying the files using MP3 Validator.
    ... and .avi movie files
    convert them to an iTunes friendly format using this free app.

  • TS3694 have an ipod touch won't allow me to add new music, tried numerous X, it will not restore to its original settings...I have tried everything that was suggested. I can have a friend restore it and I also have a click wheel ipod and it works fine.

    ipod touch stuck in restore mode. I have tried all the suggested fixes and nothing seems to work, I can have a friend restore on his pc, as this has happenned every time I attempt to add new music and etc. I have an ipod classic 120gb and everything works fine with it. What is the problem and how can I fix?
    Thank You

    Have you tried resolving the error messages by going here:
    iTunes: Specific update-and-restore error messages and advanced troubleshooting
    Also here:
    iOS: Troubleshooting backup issues in iTunes

  • My eMac won't allow me to sign into any account?

    I was given an eMac from my school and when i was doing installation test i cancelled it and it wont let me log in.

    Hi
    I'm not sure what you mean by 'installation test' but essentially I'd like to impart two thoughts.
    In addition to the eMac (the hardware) you will also need the Mac OS on CD/DVD (the software)
    It is not enough that the only instance of the OS is on the hard drive, for when difficulty strikes you'll need to apply software operations on it, which are enabled by the OS on the CD/DVD.
    If you have this disk, then it is best to reinstall a new copy of the OS onto the eMac to give a fresh start to you, the new owner. The initialisation setup  will create your email address and account name and password according to how you want it, instead of carrying over from someone else's setup from the past.
    So; 1) contact the school to get the OS disk if possible, and
    2) use it to install a fresh copy of the OS onto the eMac.

  • Firefox won't allow me to register for an account, says I'm inactive when I'm not.

    I registered for a Firefox account so I could ask a question about why Firefox 5 is not compatible with Evernote, an app which I have to have. The link was sent to my email for confirmation, and I clicked on it. Then when I went back to ask my question and was asked to sign in, I got a message back saying my account was inactive. What gives?

    You will have to provide the correct password to delete the existing account, if you have tried but are not getting the password reset email, contact Apple for assistance by going to https://expresslane.apple.com, then click More Products and Services>Apple ID>Other Apple ID Topics>Lost or forgotten Apple ID password.

  • All of a sudden I have a website that won't allow me to get into my account. I can on my desk top, but not my ipad.  Any ideas?

    All of a sudden I can't get into My Account on a website.  I can get in on my desktop, but not my ipad?  Any suggestions?

    How far do you get trying to log in?
    1. Will it not let you enter your username and password?
    2. Does it reject your known-valid username and password?
    2.1 Did you notice that it tends to uppercase the first letter of the username (possibly causing a mismatch)?
    2.2 Do you get the generic red "Please enter a correct username and/or password." message or something more specific?
    3. Does it accept them and take you somewhere useless or broken?

Maybe you are looking for

  • How to download Facebook without giving credit information

    Just bought my ipod touch and want to download Facebook and it sends me to itunes where I have to give credit information.  I DO NOT WANT TO DO THIS I ONLY WANT TO DOWNLOAD FACEBOOK FREE.  NO itunes.  Any advice.

  • Use of Field "Note" (WT_WARNTXT, Tabke name-ACWT_ITEM) in Wht button-MIRO

    Dear Experts, What is the role of Use of Field "Note" (WT_WARNTXT, Tabke name-ACWT_ITEM) in Wht button in MIRO/FB60 Transaction. For what purpose it is used. This is field is allowing for any thing to be enter. How can we make it enable so that the g

  • Logic in determining package sequence in maintenance planning

    Hi, I have created a performance based strategy, with the package containing 2 cycles and 2 levels of hierarchy. cycle 1        500H cycle 2      1000H So, the package sequence is showing 500H     1000H      1500H     2000H    2500H etc 1           2

  • Transaction processing

    Hi all, I have created a new Transaction type with Transaction category as "Sales". I want to group the different data sets for that Transaction type. Where do i do the field grouping for the same. Please suggest the path. Regards, Vinay.

  • Moving toward BI

    Hi professionals, I am working in a ALE/IDOC support project and I am an ABAP certified consultant. Now I am planning to take up BI. I have few doubts, 1. How is the job opening for an ABAP certified + BI certified person with 2+ years of experience