Mavericks - Make all new network users admin

We have a small collection of Macs at the office and are struggling with how to make all new network accounts local administrator.
What we have managed to do is make all new network users adminstrators, but only when they log on with network access to the Active Directory. In other words, network users are only administrators as long as the Mac is at the office. Once they take the Mac off the premises they are no longer local admin.
Is there a simple way to make all accounts, even network accounts, local admin? Even when the company network is unavailable?
Appreciate any help I can get!

Hi Jack,
Might try BatchMod, it's much better/easier than the Finder for recursive Permission changes, but careful, it's powerful...
http://www.lagentesoft.com/batchmod/index.html
Once launched try dropping said folder on it's Window & set as desired, check he Apply to enclosed items box too.

Similar Messages

  • How do I best integrate existing laptops for a new server?  Can I use the existing home folders on the laptops and make them into Network Users?

    How do I best integrate existing laptops for a new server?  Can I use the existing home folders on the laptops and make them into Network Users?

    Yes it will work.  I've done it for a few users in my small office.  As with anything, there are quirks that you may or may not experience.  Most quirks are app-related, due to app developers hard-coding absolute paths into their apps for things like temp files (Photoshop).  Strategies for resolving these sorts of quirks can be found via google.  You would probably have seen these quirks already when using server-based home folders for your kids.  If you haven't noticed them, then you're probably fine.
    The tech note you cited should be fine.  It doesn't explicitly say so, but you'll need to enable ssh on your server, at least temporarily, so you can upload your home folder to the server using scp, rsync, etc.  Don't try to copy the files up to the server via Finder.
    Once all your files are transferred to the server and in the right place, make sure to chown them on the server, so they are owned by the userID you created for yourself on the server.
    As with anything this involved, make a good backup of your laptop first.
    Note I have one user that isn't too happy with the responsiveness of the periodic mobile home syncing.  She has about a decade of e-mail in her home folder, probably 50 to 100 emails per day, many with attachments.  Mobile home syncing takes a long time to check and sync this huge tree of itty-bitty files, eevn with server-side file tracking turned on.  The other users are happy.
    The nice thing about mobile home syncing is that when a user "graduates" to an age where they've earned their own laptop, you can change them from a server home user to a mobile home user, with a minimum of fuss.  Also, if you lose or break a laptop, you can add a new replacement laptop to your network, and pull-down a replica of the home folder from the server, with almost no downtime.

  • How do I make a new network account visible to a client at login?

    I have just installed a new Leopard Server machine. It is an Open Directory master and I have created a number of new accounts with network home folders. On my client machines I have identified that OD server using the Directory Utility program. Yet when I log in from any of my Leopard client machines I only see local accounts, not the network accounts.
    What am I missing?
    Ian.
    --

    Did you set up your accounts on the server to be mobile or network home accounts?
    I believe they are network home accounts. For example, for the user fred I have a folder on the server hard disk called /Volumes/disk1/Users/fred, which I created as the home folder when I created the user account.
    There is a folder called "fred" visible at /Network/Servers/penguin.example.com/Users/fred/ from the client computers.
    DId you set your sharepoints up to be automount?
    I believe so. In the above example the folder /Volumes/disk1/Users is marked as a share with "Enable automount" selected and marked "Use for User home folders".
    Did you bind your computer in DIrectory Utility?
    Well, on each of the client computers I have used the Directory Utility program to connect to the OD server. Does that constitute binding?
    Is DNS resolving properly?
    Definitely. I can ping all of the computers, including the new server, from any of the computers on the network.
    I should have mentioned that I had done these things - sorry about that. Anyway, I'm stumped. Anything else to try?
    Ian.
    --

  • Cisco ISE disabled all internal Network users

    Hi All,
    Somehow, this morning when we checked on the ISE, all the IP phone users along with the internal users are disabled. We have disabled the password policy to disable the accounts if password is not changed. Our version is 1.2 and no patches. Can anyone please advise on this.
    Wireless authentication for users against AD is ok.
    Thanks

    Requiring Guests to Change Password
    You can allow or require guest users to change their password after their initial account credentials are created by the sponsor. If guest users change their passwords, sponsors cannot provide guests with their login credentials if they are lost. The sponsor must create a new guest account.
    You can either allow guests to change their passwords, or you can require that they do it at expiration and at first login. To require internal users using a guest portal to change their password upon their next login, choose Administration > Identity Management > Identities > Users . Select the specific internal user from the Network Access Users list and enable the change password check box.
    Before You Begin
    Create a Guest portal or modify the DefaultGuestPortal. This setting is specific to each Guest portal.
    Step 1 Choose Administration > Web Portal Management > Settings > Guest > Multi-Portal Configuration.
    Step 2 Check the Guest portal to update and click Edit .
    Step 3 Click the Operations tab.
    Step 4 Check either or both options:
    Allow guest users to change password
    Require guest users to change password at expiration and first login
    Step 5 Click Save .
    http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_guest_pol.html#pgfId-1462385

  • How do I make all new tabs open with my home page?

    When I open a New Tab, it opens with a blank page.
    Is there any setting which will force each New Tab to open with my Home Page?

    New Tab in Home Page: You can modify Firefox with an extension, though I personally would not want that at all, before dismissing a tab I make sure there is nothing in the tab in a backward direction, and would consider looking at anything but a blank page for a new tab as a distracting encumbrance but you can do what you ask for.
    with the following:
    *NewTabURL :: Add-ons for Firefox<br>https://addons.mozilla.org/firefox/addon/newtaburl/

  • New network user

    A coworker got married so her network account changed. She logged in now its created a new account on her computer. I'm assuming I can move all the files from the old account to the new one and the change the ownership, can somebody give me the right command line for that, thanks.

    me too - running Server.app 3.1.1

  • How do I make all new tabs open on the far right?

    I do not want to use tab groups, or have a tab open to the immediate right of current tab. Whenever I open a new tab I want it to open to the right of all other tabs.

    Type '''about:config''' in the Location Bar and hit Enter.
    ''Accept the warning message.''
    At the top in the Search bar paste this pref.
    '''browser.tabs.insertRelatedAfterCurrent''' = then lower on this pref double-click to toggle to '''false'''

  • Has mail changed so that Apple Mail is deciding to make all new email accounts IMAP?

    I am unable to create a POP mail account on my computer or my iPhone today. I have 8 other email pop accounts with the same server. Trying today to replicate the same steps with a ninth email account, APPLE Mail is deciding that it is IMAP, and will NOT let me revise the "account type".
    Does anyone know if this is a system-wide change effecting new email accounts within the past few days?

    You should be adding the Mail accounts by using System Preferences', Internet Accounts.
    Correction, that should be: You should be adding the Mail accounts by using System Preferences', "Mail, Contacts & Calendars."

  • Can not make network user accounts

    After upgrading from 10.6.8 Server to 10.8 and installing server tools, I can not make network user accounts.  All of my old network user accounts migrated to the new OS and work properly, I just can not seem to make new accounts under 10.8.
    Under 10.6.8 I would log into Workgroup Manager as diradmin and I could pretty easily make new users.
    Under 10.8.2 I launch the server app and click on "users".  The addition (+) symbol in greed out for making new users.  I can make local users via System Preferences, but I can not see any way to change local users to network users via either System Preferences or the Server app.
    I have logged into the server app using a local administrator account, the diradmin account, and the root account.  None of the accounts allow access to create new network users (addition symbol is greed out).
    Is there a trick to making network users in 10.8 that I am missing?
    (as an aside, I have noticed I can log into Directory Utility as diradmin and can view the node with all my network accounts.  It seems like I might be able to manually create a user account this way, but I'm not quite sure how to make the user record)

    Open Directory service is started and functional for all the pre-existing network user accounts that were made under 10.6.8 and earlier.  I just can not seem to create new netowork user accounts.
    I followed the steps on this page and managed to make a user record that appeared as a network user in the Server app, but I still can not seem to log in under the user I made in this fashion (dscl command via terminal).
    http://www.deadmarshes.com/Blog/20111105010130.html

  • How do I allow access to non admin network users to disk volume?

    I would like to allow access to a specific volume (disk) on one of our networked macs (Mac1) to all users. I've set user accounts on Mac 1 for all network users. These users are "regular" users, not admin. They can access this disk (and all others on Mac1) if I log in as Admin set Users to Admin. If I do this, then users have access to ALL data on all disks. If I do not, leaving them as "regular" users, when they log in they only see public folders. How can I allow access to the one disk volume without making network users admin? I tried changing various settings for the volume in Finder Info (everone else=read/write; ignore permissions) with no luck.
    Thanks
    iMac, ibooks, G5, Tibook   Mac OS X (10.4.4)  

    Your observations are correct - by default, an "admin" user connecting over AFP can choose from available "volumes" (default) or "shares", whereas a non-admin user can only mount "shares".
    By default, the only "shares" on an OS X client machine are the users' "Public" folders, and unlike pre-OS X Macs, it isn't easy to configure your own share points. Apple's official statement is that users wanting this functionality should buy OS X Server.
    However, it is possible to create an arbitrary share point using 3rd party software called "SharePoints" (donationware). I have never used it, but it seems to be well regarded. Alternatively, you can do it manually following the instructions in this hint & comments (especially apw8's):
    http://www.macosxhints.com/article.php?story=20011108161839416
    Once the external drive (or folder on the external drive) is configured as a share point, it should be possible for non-admin users to select and mount it once they connect over AFP.

  • Creating Network User

    I'm having difficulty figuring out how to create a network user account in the Server App. I'm in the "Users" pane, and I don't see an option to create a new network user. Upon choosing "create new user", there isn't an option to make anything other than a local account for the server.
    I have Open Directory turned on, and I have the server bound to the open directory server that I have set up.
    What am I missing?

    I have something very similar. Runiing a mini server on 10.9.2 and Server 3.0.
    I have a small network: server has 2 local accounts and there are about 10 network users. Not sure when, but all my network users are now showing their Home Folder location as "Custom". Clicking on the drop down menu shows only 2 additional choices, "Local only" and the name of an external disk connected to the server.Trying to create a new user gives the following choices for home folder: Local only, the external hard drive and None, Services only. Network user is not part of the choices given.
    The Mini startup disk has all the accounts I had created before, the 2 local accounts and home folders for each of my network users. Would very much like to get a few hints as to how this can be fixed.

  • Network users no being able to open/see iCloud documents

    I have a local network. All the network users are working without any glitch. They are able to use mail/contacts/etc from iCloud.
    iWork is able to open/see only local/network files but iCloud ones. Is anyone having the same problem?

    In addition, after doing this trick, if using a network user on a client machine I can see the "Mobile Documents" folder where the iCloud documents are stored (there was not such a folder before) in all my network users. However, not accesible from the iWork apps.

  • File mod date changes on all contents of user homes

    I've got network home directories shared over AFP in a small office on 10.8 mac mini server. Whenever a user logs in in the morning, all the files in his/her home directory change modification dates to the time of login. Any ideas why?
    Not sure what further details would be useful here - other than that it happens to all the network users, every morning they log in.

    So what to do about 25,500 photos dating back to 1999 all changed to Feb 2 2010?
    I can't solve your underlying problem, but I wanted to point out that there probably are utilities that will - on a batch basis - change these file dates back to whatever you want.
    If you lived in the Mac world, I'd point out that iPhoto - the Mac photo cataloging application - will reset the dates and times of selected photos to whatever you want.  So you could select folders or groups of pictures and reset their dates.
    Go to Google and see if there is a Windows-equivalent utility.  When I do a search like this on Google, I try to imagine what words or terms would be used in the product description, or on the developer's web page.  Here, I'd choose "reset date" and "pictures" and "file" and "Windows".
    This won't help you solve the underlying problem, but it might help you afterwards.
    I've started keeping an old backup hard disk in my gun safe, and only updating it in June and December.  That gives me six months to discover that something catastrophic has gone wrong with some of my files - or pictures. 
    I keep two other backup hard drives that I exchange on a weekly basis.  I could see me corrupting the relevant files on both of my weekly backup drives before I realized that I had a problem.  Hence, the need for a third long-term hard drive.
    Sure, an extra hard drive will cost you $50 to $100.  How much time will you have to spend trying to recover from this?

  • Network user can't see local home directory

    Hi there,
    I have a Mac Mini running Lion Server with Directory Services turned on. I've been using this to allow network users to log into Lion clients, as well as set up mobile accounts. This has been working fine.
    Now I've just created a new network user for use with a Mountain Lion client and have experienced some strangeness with this new user's home directory. The binding to the directory was fine, and the credentials for the network user were fine. However, when logged in, this new user has his home drive mapped to /Network/Servers/<servername>/Users/<username> rather than the expected /Users/<username>. This has bad side-effects. For instance, Chrome tries to save downloads to the server instead of locally.
    What I can't work out is why the home directory isn't pointing to a local location. The other users (on Lion) have the same home directories defined in their Open  Directory profiles. The only difference is the new user is on Mountain Lion, but I don't think this has any bearing to the problem.
    Can anyone offer some advice?
    Benjamin

    So I took my Mac Mini running OS X 10.8 Server, along with two client laptops: one exhibiting the problem I described, and the other where network logins and home directories worked as intended.
    Long story short, the guys at the Bar couldn't figure it out. The user definitions in Open Directory seemed ok, but they still couldn't work out why no local home directories were being created. Not sure if this helps, but in trouble-shooting, we also discovered that trying to login with a network user on the problematic laptop didn't work when the server wasn't on the network. It's as if the server is required to be present.
    Anyway, the case has been referred to the business team, which is supposed to have more expertise with OS X Server.

  • New Extreme = new network?

    I have been using an Express for internet and have just bought an Extreme so I can move the Express to the HiFi for AirTunes duty via a WDS.
    I guess I need to make a new network with the new Extreme as the base station and if so do I delete the old network first and is this easy?
    Thanks for your input,
    Michael.

    In the good ol' days phono jacks often required a preamp, if you had a nice turntable...
    iMPH, do me a favor and broadcast again how painless that was. A lot of issues I see here would be simply solved if people would reset and restart.
    And one of the thread veterans left a link to a how-to page I wish I coulda found:
    The title of the link is AirPort Extreme and Express: Using WDS to create a network from multiple base stations (I don't know how to mark up a link...)
    here is where it is found:
    http://docs.info.apple.com/article.html?artnum=107454

Maybe you are looking for

  • Question about "words with friends" rules-can more than 1 person play on the same Ipod device?

    I have a Ipod touch 5th Generation and I like to play the free game version of "Words with Friends"  Can other family members in my house sign up to play on my Ipod using a different user name?  I have tried to figure this part out and there's no clu

  • Port 0 error with mail connection HELP!

    Hello all I have seen this topic on the forum before but all the solutions out there have not worked. I have worked on my school's wireless network for more than a year now and have had no problem using apple's mail to access .mac mail and g-mail mai

  • Read Out Loud Accessibility

    I am not able to use "read out loud" for a pdf book file.  I get this error "Read out loud cannot be activated for this document because it's permissions do not allow for content copying for accessibility." I checked under document restrictions and t

  • Access denied when connecting Integration Services service`

    Hi ya, I'm using my own Windows user. Such user belong to Admin group. What's more, my Integration Services is started using this same user. What's happening here?  Any advice or help would be very appreciated, Version: Microsoft SQL Server Managemen

  • Apple Alternate ID

    How do I remove my or change my ALTERNATE APPLE ID?