View/Change User Accounts From Across The Network - Do not have Server

Is there a program or utility that can be run in Mac OS X Tiger or Leopard to manage user accounts on other Macs that are located across the network? Is there anything that will do this that is free, or not too much money?
Our setup: multiple Macs on a network that is primarily a Windows AD Domain. For various reasons, we do not have the Macs setup as members of AD. We also do not have a Mac OS X Server. I am wondering if there is something that is built-in, free, or on the cheaper-end, to manage user accounts and their permissions from across the network on the Macs?
Thank you for your help!
Dan

If the systems are not bound to a parent domain, then local account policy will need to be set individually. There is a way to get Workgroup Manager working on OS X client, but I do not know of a way for it to see remote NetInfo/DS Local data stores. It will only see the local store. NetInfo in the 10.2 days could pull this off. But Apple removed those features in favor of LDAP and eventually DS Local.
You will probably need to use a combination of tools. Start with defining base settings in the User Template to ensure that all new home folders are created equal. Then use ARD or ssh to define user policy with pwpolicy and other tools like niutil (Tiger) or dscl. Test with mcxquery. If you get Server Admin Tools, you can use Workgroup Manager to craft the needed xml for mcx values, then inject into the user account.
But this is only going to get you local policy. If users are connecting to file shares and mail, they are using their network credentials so those policies need to be managed at the domain level.
I would encourage binding the machines to the domain. While this can, and has (sadly), been done, being part of the domain is so much easier. If you need a system for storing the LDAP schema, get a Mini and do it on the cheap. Otherwise, consider AD schema modification and then practice your xml skills.
Hope this helps

Similar Messages

  • I have trouble creating a pdf portfolio from Outlook: the result does not have "From" or "Subject"

    I have trouble creating a pdf portfolio from Outlook: it creates the portfolio, but the result does not have "From" or "Subject" in the index.  Please help!

    Thank you, I am aware of this function.  The fields are present, but blank.  (It seems that the data is not getting exported…)
    Please keep trying to help me!
    -Nancie

  • Change user account from mac to mac

    Witch steps are required for copy the iTunes Account from the old Mac mini to the new Mac Book Pro?  The old Mac mini it isn't in operation. I need only the iTunes Account for the iPhone, Music and ohters.

    Unfortunately the 'require password change at next login' option is badly phrased and unsuitable for you.  If this checkbox is set, the only thing the user can do with their account is log into it on a Mac using a standard Mac login screen.  Logging in in this way will automatically trigger the 'enter your new password' dialog.  Attempts to use the account with other services will lead to an error message like 'account disabled' or 'no such username/pasword'.
    Since your users are not using Macs to log in, this option is useless to you.
    You can allow your users to change their passwords remotely, no matter whether they're using Macs or Windows or iPads, by enabling the 'change password' option which, I think, is part of the wiki service.  This gives you a web-facing 'change password' page which can be used from any web browser.  However, even this option will not work if you set the 'require password change at next login' option.  No, it makes no sense to me either.

  • User Accounts in Domain Admins group do not have full administrative rights to the server

    Our server was fine until recently one day we lost admin access for admin user accounts. If we log in to the server with the Domain Admin account, this account has full admin access to the server and can install and launch all programs and even all server
    admin tools. If we log into the server with a user account which is in the Domain Admins group, that account cannot install software or launch Services.MSC. Even IE will not load any page and crash with a "Not Responding" Error.
    The server has no viruses we even ran SFC /SCANNOW and it did repair from corrupted files but that didn't fix the issue.
    Any ideas?

    Hi Rick,
    May be UAC is blocking installtion. Have it disabled and see if it helps.  Ensure you have domain admin groups added into local administrators group.
    Alos Check these links please.
    https://social.technet.microsoft.com/Forums/en-US/b5300f28-6a2a-4760-8b80-97a2da0f87c1/2012-domain-admin-user-cannot-install-programs-on-a-domain-windows-7-pc?forum=winserverDS
    https://social.technet.microsoft.com/Forums/en-US/0ca040de-52ac-4259-bf78-c22436fd04d4/domain-users-with-domain-admins-right-cannot-install-programs-or-open-server-manager?forum=winserverDS
    Thanks,
    Umesh.S.K

  • How do I change my account from New Zealand to Canada? Have 17$ but if I have to lose it so be it.  BonZambia

    How do I change my iTones account from New Zealand to Canada?

    Are you moving to Canada?
    You can ask Apple to set the balance to zero (personally I would spend it down as much as possible).
    iTunes Customer Service Contact - http://www.apple.com/support/itunes/contact.html
    App Store Frequently Asked Questions (FAQ) - http://support.apple.com/kb/HT2001 when using iTunes --> "To change countries, scroll to the end of the iTunes Store home page and click the flag indicating the current country. To choose a different country, click the appropriate flag."

  • MAXDB user / password to drop the database - do not have

    *Hello,*
    *I am installing the SAPNWABAP701SR1_trial on one of our windows XP laptops and do not have the MAXDB user / password to drop the database which was built when a previous ABAP trial version was installed back in 2007.*
    *Is there any way short of reformatting the drive to drop the database?*
    *Thank you,*
    *Emmett*

    SAP Utilities       c:/sapdb/programs        7.6.02.14     32 bit    valid
    Server Utilities    c:/sapdb/programs        7.6.02.14     32 bit    valid
    Base                c:/sapdb/programs        7.6.02.14     32 bit    valid
    JDBC                c:/sapdb/programs        7.6.03.02               valid
    Messages            c:/sapdb/programs        MSG 0.5028              valid
    ODBC                c:/sapdb/programs        7.6.02.14     32 bit    valid
    Database Kernel     c:/sapdb/nsp/db          7.6.02.14     32 bit    valid
    SQLDBC              c:/sapdb/programs        7.6.02.14     32 bit    valid
    Webtools            c:/sapdb/programs/web    7.6.00.32     32 bit    valid
    SQLDBC 76           c:/sapdb/programs        7.6.02.14     32 bit    valid
    No another databases installed/running on your server.
    dbmcli inst_enum: 
    7.6.02.14    C:\sapdb\NSP\db
    dbmcli db_enum:
    NSP     C:\sapdb\NSP\db                             7.6.02.14     fast     running
    NSP     C:\sapdb\NSP\db                             7.6.02.14     quick     offline
    NSP     C:\sapdb\NSP\db                             7.6.02.14     slow     offline
    NSP     C:\sapdb\NSP\db                             7.6.02.14     test     offline
    I am an not an SAP customer. I have been an ABAP consultant since 1995.
    Edited by: eballard on Jul 29, 2010 7:23 PM

  • I just changed my account from the UK to the USA. Now, most of my songs are not available. How do i get them authorized?

    I just changed my account from the UK to the USA. Now, most of my songs are not available. How do i get them authorized?

    Downloading past purchases from the App Store, iBookstore, and iTunes Store
    iOS- How to transfer or sync content to your computer
    iTunes Store- Transferring purchases from your iOS device or iPod to a computer
    If you have non-purchased content then you need to use third-party software to transfer it to your iTunes Library - Phone to Mac - Pod to Mac.

  • TS2972 I cannot seem to get all of my music shared across the network from my MacBook Pro to my iPad. This was not an issue a few days ago. Can anyone help?

    I cannot seem to get all of my music shared across the network from my MacBook Pro to my iPad. This was not an issue a few days ago. I can see all my songs if sorted that way, but if i sort by artist, only a few of them are present. Can anyone help or have any insight?

    Well I didn't think of it before, but I logged out of my apple ID othe iPad's home sharing. The I logged back in and it worked. It's a little weird, but I will take it. Thanks!

  • How do you delete a guest user account from the users&groups pane?

    could anyone help with giving a tip on how to  delete a guest user account from the users&groups pane in os-x 10.7 ? when I unlock account the delete or minus button is inactive. Thankyou

    aha, by disabling the find my mac checkbox in icloud seems to work. tusen takk previous threaders!!!!!!!!!!

  • HT1918 Change iTunes account from Master Card to the Free account

    Change iTunes account from Master Card to the Free account

    You won't be able to redownload any of your UK purchases whilst you are in the US, you have to be in a country to use its store - and you can't merge purchases from two accounts or countries. No content should be removed from your device or computer's iTunes library if you change the country on your account, or create a new account and log into it.

  • Migrating local user accounts/home directories to network user accounts

    Hi,
    I am planning on moving the user accounts from several Mac OS X client machines to a new Mac OS X Server machine (Quad core Xeon MacPro). I am very familiar with OS X client in a support environment, but do not have extensive experience with Server.
    I read over the instructions in this article
    http://docs.info.apple.com/article.html?path=ServerAdmin/10.4/en/c6um3.html
    and it appears to be fairly straight forward, although I do have some questions regarding the existing data (home folders) and how to set the clients to log in to the network account.
    Previously, in the event that I have needed to move a person's home directory to a new computer or recover from a corrupt OS (and Archive&install was not an option), in OS X client I would:
    1) Back up the home directory.
    2) Erase/reinstall OS X client.
    3) Log in as Root.
    4) Go into "Accounts" pref pane and create user with same short name as original/backed-up home directory.
    5) Replace the newly created home directory with the backed-up home directory.
    6) Go into Terminal and chown/chgrp the home directory to username/staff, respectively.
    This would result in a perfectly migrated user account. All settings and files working just as they did on the previous system/install of OS X.
    First Question: Could I employee a similar method to retain the content and settings from the local user accounts on the server as I migrate them to network users? Moving the user accounts to the server as described, then running terminal to set proper ownership...
    Second Question: What do I do on each client system to tell it to recognize the networked home directory for each user? Do I just change the user's home folder path in Netinfo Manager to the automount location?
    Thanks in advance for any help you can offer,
    -David
    MacPro 2.66 Quad Core (MA356LL/A)     Mac OS X Server 10.4.8

    A network account is really existing only on the server but if you use "portable homefolders" (Tiger client and server) you could "migrate" the local account to a "server" one by:
    Login locally as another user with administrative rights.
    Change the name of the old account folder in /Users.
    Remove the "old" account locally (woun't remove the "old" folder as you changed the name) only Netinfo data.
    Login using the serveraccount login/password thus creating a homefolder on the server.
    Logout and back in, enable portable homefolder.
    Logout and then in as a local admin and remove the new user folder.
    Change the name on the old userfolder to what the new one had.
    I'm not a 100% sure Netinfo has the server account UID now (added by logging in and creating the portable account?) but if it does:
    (http://forums.macosxhints.com/archive/index.php/t-12077.html)
    "Finding and changing UIDs across the filesystem is a one-liner command:
    sudo find / -user UID -exec chown userName {} \;
    (replace UID with the old UID number and userName with the new user name to associate file ownership.)"
    (A portable account must have got some "kind" of UID?)
    Let the machine "sync" with the server account.
    If you want an "on network only" account I don't know what you need to remove locally afterwards.
    HTH

  • How to restrict from creating the  Network for  1st & 2nd level  WBS

    Hi All,
        In our project structure we have up to 5 levels of WBS, In some cases we have creates  3 level also . Now we want to restrict creates Network for first two level WBS  , actually we want to restrict user to Create PR for those WBS so if we restrict them from creation of Network for 1st &  2nd level then they not able to create PR for same  .
    Thanks,
    Virendra

    Hi Virendra,
    I can suggest you other way round solution.
    If you are sure that those two WBS will not take any actual or commitment cost, then its better to NOT to mark those WBS elements as Account Assignment Element. I mean, if you do not set the indicator of Acct. Assignment Element (Untick Acct Assignment Element) on those WBS, then user will not be able to create Networks on those WBS Elements. Try this on your development or quality client and let me know if it works.
    If it works, then you just need to disabled the Acct. Assignment Element indicator for those two WBS element and you can achieve that through substitution and field selection of WBS as well.
    OR
    Just look at OPSG settings at tab component. Just look if that can solve your purpose because your requirement is to stop PR from those WBS element. (I am just wondering if you can stop user from creating/change material components from those WBS-Networks)
    OR
    Go for User Status and set it to on those WBS Elements. Object Types will be Networks and Network Header.
    OR
    Try to achieve a validation or substitution where in you can mark Res./Pur. Req as 1 (Never) only for those two WBS elements. In this way user cannot create PR on those two WBS elements.
    Regards,
    Amit

  • How do I run a user account from an external HD?

    How do I run a user account from an external HD? I will be away from my desktop iMac and want to use our MacBook Pro overseas for two months with my iMac user account copied to an external drive.

    1. WARNING: This procedure is for advanced users only. Some third-party software may not work as expected, or may not work at all, if the home folder is moved.
    2. Back up all data.
    3. Copy your home folder to the desired location, which must be on a volume of type "Mac OS Extended (Journaled)" with file ownership enabled, as shown in the Finder Info dialog. Encryption is optional. The volume must be on a local storage device, not on the network, and it must be mounted automatically at startup — before any user logs in. A disk image will not work.
    The name of your home folder is your short user name. Do not rename it. Do not copy the "Users" folder.
    5. Select
     ▹ System Preferences ▹ Users & Groups
    Click the lock icon and authenticate. Right-click or control-click your name in the account list, and select Advanced options from the popup menu. In the sheet that opens, change the location of the home directory. Log out and log back in.
    6. Test. If you have problems, reverse the above steps. If you got this far, you should have no trouble doing that. If everything works as you expect, delete the original home folder.

  • Migrating current mobile user accounts from one OS X Server to another

    I have not been able to find ANY answers to my situlaton. 
    I have a small office that currently has a Mac Server 10.4.11 server running that has many "mobile user" accounts setup.  This was done because we have so many mobile users coming in and out of the office.  When the user comes back they sync their home directory witht th server here.  Works great.
    We recently purchased a new Mac Server running 10.7.4.  Set it up as the Open Directory Master.  I unbind from the old server and bind to the new server.  Everything seems to be working just fine except when I go and add a current mobile user to the new server it creates a new user account on the client device (MacBooks) as if the previous user settings didn't exsist.  Since they need to be mobile users and not just network users I haven't been able to find a solution to this problem any where.
    Is there a way on the client to tell it to use the old user account stored on the MacBook to use with new mobile user connected to the new server?
    Or is there an easier way of doing this that I don't know about?
    Thanks,
    TK

    If I understand what you wrote, no.  The reason is this.  If memory serves...  In 10.4.11 accounts were assigned a UID.  In 10.7.x, accounts are assigned a UID and a GUID.  Most everything relies on the GUID at this point.  So, what you have is an account named marysue on the workstation and it is assigned a UID like 1045.  Now you created marysue on the Lion server, but you likely did not recreate the UID to match the old server.  And thus, the UID value is different but more importantly you now have a GUID value like EC0F9357-8EF2-4D3B-B6F3-2E3016400114, that is associated with the account.  So, the user, despite having the same shortname, is different. 
    In addition, you are working with two different directory systems.  10.4 still used NetInfo (ah, I miss you so).  10.5 and above use DS local flat files, even when bound to an LDAP system.
    So, probably the easiest way to do this, provided I understand what you are seeing is the following.  Let's assume the following:
    You have a mobile account on a workstation for the user maryjoe with a UID of 1034 that came from the 10.4.11 system.  You have this account cached.  You have a home folder in /Users/maryjoe.  You have now bound to the new server which contains a user named maryjoe likely with a UID of something other than 1034 and with a GUID value that likely did not exist in the old directory system, also with the shortname of maryjoe and a home path of /Users/maryjoe.
    So when you log in, you are likely being pathed to /Users/maryjoe, but you are seeing a default Dock and no documents because of permissions.  My guess is that if you used Terminal to view the Users directory you would see something like this (open Terminal and issue the command ls -l /Users/:
    drwxrwxrwt   4 root       wheel  136 Apr 18 21:35 Shared
    drwxr-xr-x+ 14 locadmin  staff  476 Jan 21 7:42 locadmin
    drwxr-xr-x+ 14 1034  staff  476 Mar 21 10:42 maryjoe
    Note the folder maryjoe is not owned by maryjoe, it is owned by the UID of maryjoe from the old server.
    Ok, so long story short (sorry for the log explanation, especially if you are experiencing something else that I did not get from the post), all you need to do is update the permissions of the home folder.  Do this:
    1:  Log in as the local admin
    2:  Open Terminal
    3:  Issue this command:
         sudo chown -R maryjoe /Users/maryjoe
    Even with a lot of data in the home folder, this should not take more than a few minutes to complete.
    When the command completes, run this command again:  ls -l /Users/
    You should now see
    drwxrwxrwt   4 root       wheel  136 Apr 18 21:35 Shared
    drwxr-xr-x+ 14 locadmin  staff  476 Jan 21 7:42 locadmin
    drwxr-xr-x+ 14 maryjoe  staff  476 Mar 21 10:42 maryjoe
    Now try logging in as the user.  With a little luck I divined the issue and this will have you up and running.  Now, I normally will also purge the cached account in /var/db/dslocal/nodes/Default/users/ but that might be a bit daunting.  So let's start with the simple process first of ensuring home folder permissions are correct.

  • HT2731 How can i change my account from US to Ireland setting. I can get apps as my account says US? Pls help rhanks.

    HOw can i change my account from US to Ireland setting as i cant install apps in Ireland. Pls help

    Change iTunes Store Country on an iDevice
    1. Tap Settings;
    2. Tap iTunes & App Stores;
    3. Tap View Apple ID;
    4. Enter your user name and password;
    5. Tap Country/Region;
    6. Tap Change Country/Region;
    7. Select the region where you will be located;
    8. Tap Done.
    Also, see How to Change Your iTunes Store Account Location | eHow.com.

Maybe you are looking for

  • Adding folders to itunes from my hard drive

    hi, i hope this is the right place to post, sorry if it's not...i am new to itunes, i just got an ipod today, and after downloading, installing, and loading itunes, i went to file, add folder to library, and selected the folder on my hard drive where

  • Next record

    I'm using vb script. I'm making a quiz. I connect to a database for the questions and choices. I have a test page and a test processor page. On the test page I display the question and 4 choices. On the test processor page, it tallies up the score an

  • ICloud invites on non-iCloud e-mail address in iCal

    Hi all, I'm not sure if this is even possible, or maybe it's very basic functionality.. Anyway, sometimes I receive iCal-created events in my work e-mail, which is just a regular IMAP account at a regular Linux server. Of course, accepting these even

  • In order related billing its possible to have split invoice

    hello, In order level i am getting two line  items which are order related billing,can i split the invoice in to two,for two line items. please guide me

  • Events management in iPhoto 2008.

    Dear members: After the upgrade to iPhoto 2008 with the new Events feature I noticed that the way the application organized the Events is less than ideal for my needs. I want to overide iPhoto and create my Events manually based on my own needs. Ques