Permissions issue binding and logging into Active directory

Hello:
We're having an issue with file permissions when our Macs connect to SMB shares via AD.  We bind the macs to the active directory but when the users connect to the SMB shares (Go connect to server smb://.......)  they see everything on the drive not just their shares.   Is there a setting in the Directory utility that will only allow the user to see their shares or is this an issue on the windows side of the house. The windows users do not have this problem.  Any help would be greatly appreciated.
Thanks, Rick
Mac Clients are running 10.6 thru 10.8

Also be aware of Apple's white paper on this:
http://training.apple.com/pdf/wp_integrating_active_directory_ml.pdf
A wide variety of IT-focused white papers are available here:
http://training.apple.com/osx

Similar Messages

  • EMacs cant log into active directory anymore

    Hello,
    I'm hoping you can give me some insight as to what is going on.
    We run an active directory network which is basically all PCs.
    We do however have two rooms with 12 eMacs in them each. Up until mid December they had been mostly fine but what we are exeriencing now is that they are having real difficulty logging into the active directory.
    If i click on the names of the machines eventually i will see one of three things:
    1. Green dot- network accounts available. These we can log into.
    2. Yellow dot - some network accounts available. These we cant log into.
    3. Red dot - no network accounts available. These we cant log into.
    My knowledge of Macs is about a 3 on a scale of 1 to 10.
    The DHCP server is server 2003
    The eMacs are running OS X 10.4.11
    I can log into them as local administrator and can browse the network and even get onto the internet when they are unable to log onto Active directory.
    What ive done so far...
    1. If i unbind and then rebind the mac using directory access they can log in for a while but then randomly they change so that we cant log into them anymore.
    2. gave each of the macs an ip reservation on the dhcp server so that they always pick up the same ip address.
    3. removed them from Active directory and re added them. even gave them different names.
    4. Changed out the switch they were plugged into.
    none of these has solved the issue so far so im hoping that someone might have seen something like this before...
    thank you.

    Hi halo511, and a warm welcome to the forums!
    My knowledge of Win/2003 is about 3 on a scale of 1 to 100!
    I wonder if these might help...
    http://support.microsoft.com/kb/834498
    http://www.macwindows.com/Win2003.html
    http://www.macosxhints.com/article.php?story=20050302023720578
    http://allinthehead.com/retro/218/accessing-a-windows-2003-share-from-os-x
    Does the Server have more than 1 NIC?
    http://forum.soft32.com/mac/Windows-Server-2003-MacIntosh-ftopict7128.html
    For stubborn Mac<->Windows® problems...
    http://www.thursby.com/products/admitmac.html

  • Directory Security Strange Permissions Issues (Windows Server 2003 running Active Directory)

    I have a user that all of a sudden was not able to open 70% of her files located on a file server, Windows Server 2003 running Active Directory, from her laptop. The same user can access all the same files from a different machine, logging on with the same
    credentials. Just looking for a point in the right direction and a possible theory as what could cause this problem, an why all of a sudden. I did go back through the logs but nothing sticks out. For the most part the logs on the server and the laptop are
    pretty clean. 
    Both machines are Latitude E5420s running Windows 7 Enterprise Service Pack 1. Both machines are 64bit and connect to the network via hard-wire, not wireless.
    Thanks in advanced.
    Grajek

    I would recommend proceeding that way:
    Check that your DCs are in a healthy state and AD replication is fine: It might be that the user is member of security groups and the membership is not getting replicated properly which can cause this random behavior. You can use
    dcdiag and repadmin for checks and you can refer to my recommendations here: http://social.technet.microsoft.com/wiki/contents/articles/18513.active-directory-replication-issues-basic-troubleshooting-steps-single-ad-domain-in-a-single-ad-forest.aspx
    Make  sure that the file server is reachable from the user client computer. Start with
    ping and nslookup. Also, you need to make sure that the traffic between the client and the server is not blocked or filtered. You might want to temporary disable security software for testing
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • Delete local accounts created when logging into Active Directory?

    When a user logs into their Mac using their Active Directory credentials, a new local user folder is created that corresponds to their login name. But a new account doesn't show up in the System Preferences Accounts. So how do I go about deleting this local account? Can I simply delete their Users folder?
    Thanks.
    G4 (model M8839LL/A)   Mac OS X (10.4.8)  

    AD does this with Windows, too. This is because the AD account is not the same as the local account. If you have a user with the username joeuser, and he has a local account named joeuser, he'll have a home directory in that name. If he logs into and AD system with the domain name ADDomain, there will then be an account with a name something like joeuser.ADDOMAIN, which, by definition, is not the same as the account joeuser. On a Windows box, at the same time as the joeuser.ADDOMAIN account is created the joeuser account will have its name changed; if the box's name is joe's_mac, the joeuser account will become joeuser.JOE'S_MAC. This kind of thing will apply only to users who have both local and domain accounts. Users who have only local accounts, such as jilluser, will not have their account name changed. Users who have only domain accounts, such as bobdomain, will not have their account name changed. Users will not notice any difference in the way they log in; they will log into their domain account, and see just what that account has access to, or will log into their local account, and see just what that local account has acces too, depending only on how they set the login box. They will never have to enter joeuser.ADDOMAIN, just joeuser... and the domain name in the proper place.
    If you delete the domain account, a new one will be automatically generated as soon as the user logs back in using a domain account. Any data stored in that account will be deleted when you delete the account.

  • Error trying to log into Oracle Directory Manager

    I am receiving an error message when I try to log into Oracle Directory Manager. This is the first time I am trying to log in, I am trying to login with the username cn=orcladmin, and with the password welcome, which is the default. I then receive the error message "Server is not up and running". I thought I started an OID instance with oidctl.
    I am running on w2k.
    I am using the default port 389, at least thats what I accepted while installing the infrastructre.
    Any advise?

    From the main page for this forum (http://forums.adobe.com/community/creative_cloud) please see the announcement.
    Creative Cloud is experiencing issues at this time.  We are investigating and working to restore service as soon as possible.  This post will be removed once the issue is solved.

  • Log into Activity Analysis (EPO)

    Hello,
    I have a problem since Friday, 31st October and basically I cannot log into Activity Analysis (EPO) but my colleagues can. I have contacted support.BOSAPEMEA_sap.com and they refer me to this Web site.  It was very complicated to log a tickets with EPO Help Desk, sorry to telling that but for 'common' user like there is not an obvious option named "log your query". I still do not know if here is a right place to log a ticket?
    The error message is "An error has occurred. Error code 8088021.General Data base error.Class CUserInfo . GeneralRowSetOpenError."
    Please could you advice what cause the problem and options to resolve it. 
    I would very appreciate if you could answer by tomorrow evening for example....
    Also if you have a guide how to log a query on your WEb please could you sent me?
    Regards,  Valentina

    Hi Valentina
    I'm sorry you have had problems raising an incident through the Service Marketplace - I will send you details on how to request support outside this thread as there is no way to attach a document to a forum thread that I can see.
    One of your colleagues has raised this error as a support request, and to my knowledge the issue has now been resolved following a server reboot. Your error message indicates a there being a problem with your client machine connecting to the database server via the application server, so it is possible that the connection had been dropped and the reboot restored that machine-to-machine communication.
    Kind regards
    Fiona

  • I just bought a (used) Iphone 3gs for wife and it had angry birds and $89 Navigation on it (I paid extra for it).  Once updated and logged into my I-tunes it no longer works? How can I make those apps work?

    I just bought a (used) Iphone 3gs for wife and it had angry birds and $89 Navigation on it (I paid extra for it).  Once updated and logged into my I-tunes it no longer works? How can I make those apps work?

    Apple doesn't have anything to do with this other than enforcing the DRM protection. The developers of this content expect to be paid if someone wants to use their content. When you purchase content in the app store, you purchase a license to use the content. This license does not permit you or anyone else to resell or give this content away. The individual you purchased the phone from simply does not have the right to sell or give away any purchased content on the phone. You were deceived.

  • How to import Photos into Active Directory

    Hi -
    IT Director asked me to import employees pictures into Active Directory so that we can use them in Outlook, SharePoint, Lync etc.
    Do you know how to import pictures into Active Directory?

    Thumbnailphoto Attribute in active directory is responsible for adding photos to Active directory.
    By Default Replication of this attribute will be disabled to Global catalog server. To make use of this facility we will have to enable replication of this attribute to Global Catalog. ( To accomplish this you will have to edit the schema using Active directory
    schema snap in).
    Refer Below link which explains about enabling the replication of Thumbnailphoto attribute to Global catalog.
    http://www.msexchange.org/articles_tutorials/exchange-server-2010/management-administration/configuring-using-display-picture-exchange-server-2010.html
    Requirements
    Minimum requirement for your exchange enviornment to use this - Exchange 2010.
    Exchange 2007 Don't support uploading photos AFAIK.
    Domain controller should be running with atleast windows server 2008 or later. And
    schema has to be windows server 2008
    Additionally for your information,
    How to remove the uploaded photos?
    Either You can edit the Thumbnailphoto attribute using ADSIedit and remove the entry which is assocaited with Thumbnailphoto attribute.
    Or,
    Try this.
    The Import-RecipientDataProperty and Export-RecipientDataProperty cmdlets allow you to import and export the photo blob to and from
    thumbnailPhoto attribute, but there's no Remove-RecipientDataProperty cmdlet to remove it. You can use the
    RemovePicture switch of Set-Mailbox cmdlet to remove a user's photo. For example:
    Set-Mailbox "Bharat Suneja" -RemovePicture
    Check out the below link which explains in and out of uploading photos,
    http://blogs.technet.com/b/exchange/archive/2010/06/01/gal-photos-frequently-asked-questions.aspx
    http://blogs.technet.com/b/ilvancri/archive/2009/11/17/upload-picture-in-outlook-2010-using-the-exchange-management-shell-exchange-2010.aspx
    To know about uploading photo using powershell ask this question in powershell forum
    http://social.technet.microsoft.com/Forums/en-US/winserverpowershell/threads
    Regards,
    _Prashant_
    MCSA|MCITP SA|Microsoft Exchange 2003 Blog - http://prashant1987.wordpress.com Disclaimer: This posting is provided AS-IS with no warranties/guarantees and confers no rights.

  • My macbook wont allow me to use the same hotmail address as i used on my other computers. How can I keep the same email and log into it on a macbook?

    my macbook wont allow me to use the same hotmail address as i used on my other computers. How can I keep the same email and log into it on a macbook?

    That indicates a hardware failure. Read here:
    http://support.apple.com/kb/ts1559
    If nothing works, you most likely have a hardware failure. Make an appointment at an Apple store to confirm.

  • I try and log into icloud but the get the message valid apple id but not an icloud account. help anyone

    I try and log into icloud but it wont let me. It saya my appleid is valid but I dont have an icloud account. how do I get one?

    Welcome to the Apple Support Communities
    You have to log in iCloud on an iPhone, iPod touch, iPad or Mac first before being able to use iCloud on your PC. See > http://www.apple.com/icloud/setup
    If you haven't got an iPhone, iPod touch, iPad or Mac, you can't use iCloud

  • I have connected my ipad to my computer and logged into iTunes website. To restore my Ipad I have chosen language, country then it asks you to connect with cable and log into iTunes, I have done that, but cannot find this other information I need to resto

    I have connected my ipad to my computer and logged into iTunes website. On my iPad to restore my my data Ipad I have chosen language, country then it asks you to connect with cable and log into iTunes, I have done that, but cannot find this other information I need to restore from the website. Can you help me please? the 2 replies, I thank you, but this has not helped with my problem.

    Your post is somewhat confusing. To restore your iPad you use the iTunes application on your computer and connect your iPad. Select your iPad in the left column of iTunes on your computer and select General in the right column. You should find the restore choice there.

  • How do i put my songs onto a cd and log into my account?

    i just downloaded this to my computer i usually do it on my phone how do i put my songs onto a cd and log into my account on the computer it wont let me
    <Re-Titled By Host>

    Downloaded what? No idea what you're talking about.
    Please have your keyboard checked. It seems the punctuation keys are not functioning, making it difficult to read your post.

  • When I try and log into imessages, I get a message that says my email address is already in use

    When I try and log into imessages, I get a message that says my email address is already in use. What do I do?

    Yo,
    If u use [email protected] to log in (ur apple id) then u have to use a different one like [email protected]
    Mark this as helped if it does... thx

  • Could we have same name's for User and Groups in Active directory

    When iam trying to create a user name " Logistics " under a OU, I am getting a error
    "The pre-windows 2000 logon name you have chosen is already in use in this domain. Choose  aother pre-windows logon name, and then try again"
    We already have a group by the name " Logistics "
    Could we have same name's for User and Groups in Active directory?
    Thanks in Advance

    sAMaccountName attribute is unique. So, the short answer is you cannot.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • My Macbook Pro's iTunes App was logged in as someone else. I logged out of that account and logged into mine, but I found that the app still shows all of the previous account's content. None of my apps, songs, or movies are there!

    My Macbook Pro's iTunes App was logged in as someone else. I logged out of that account and logged into mine, but I found that the app still shows all of the previous account's content. None of my apps, songs, or movies are there! iTunes 12.1.0.50 on OS X Yosemite version 10.10. Why is iCloud doing this, and how do I view my content again?

    MacBook Pro  / Mozilla Firefox / Netflix / Silverlight Update solved - DON'T DWNLOAD FROM NETFLIX
    I solved this problem tonight. I have a MacBook Pro with 10.5.8. I know, it's old. But I love my Netflix and I recently noticed that Firefox plays Netflix much better.  Then I suddenly got this message that I needed to download the latest Silverlight - it only takes 30 seconds! - WRONG.   However, after much searching, I finally did the steps in order and it worked.  
    This was after repeatedly downloading Silverlight from the Netflix site without success.  So here's what I did:
    1. Went to http://www.microsoft.com/getsilverlight/Get-Started/Install/Default.aspx
    2. Followed the directions. I felt like such an idiot for not doing it right before.
    3. Go to your hard drive and search for "Silverlight" to locate ANY existing Silverlight files: .dmg, etc.
        [also check your Libary/ Internet Plug-ins, but the above search is faster]
    4. Drag it all to the trash and empty it.
    5. Go back to the Get  Silverlight page and click on the Install on that page, not the Netflix site.
    6. Note the steps for Safari or Mozilla Firefox - I wanted Firefox, so I follwed those instructions.
    7. Once it's installed, close all the browsers and Restart that bad boy. Right away.
    8. Open a browser, go to Netflix and proceed to joyfully rot your brain with Netflix content. Yay!

Maybe you are looking for

  • In PS and AI in CS2, when I open a picture folder, the thumbnail images are inverted

    I recently D/L installed CS 2 on my Windows 7 desktop. Thanks Adobe, it's great for me. However, when I open a folder in PS or AI to select an image, the thumbnails in the folder are inverted. Strangely, this doesn't happen on my Windows 7 laptop. Ca

  • Manual update of Forecast/Demand and Stock data in SNC5.1

    Can we update the Stock in Hand at customer's place when we receive these values every monday by email? So after getting these figures on every monday we want to update it in SNC5.1 manually. Is it possible? If yes then how? What is the impact? Thx

  • Where to find self service log

    Hi, I have setup self service portal under Enterprise Infrastructure Cloud on EM12c. When a SSA user requests a server using a template, the request fails with "Execution Error" and no other detail on Self Service Portal Screen. Do any one one know h

  • Regarding Linux Installation

    Hi, Today i bought the ideapad y530-40512uu laptop. I want to install linux in this laptop. Please give some information about how to install linux in this laptop. In the installation if my windows corrupt means how can i recover my windows vista. Fo

  • JMenu and JMenuItems

    hi does anybody know how i can disable menuitems and enable them on some given events? would help me very much! thanx