Re: Getting MacBook Pro to authenticate with AD (SBS environment)

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



In article <O4jdU7PGHHA.1252@xxxxxxxxxxxxxxxxxxxx>,
"Helen Mooc" <hmooc@xxxxxxxxxx> wrote:

Good evening!

Just wondering if any of you geniuses have been able to get MacBook Pro to
authenticate with SBS server and still able to log in after taking the
notebook off of the network. For the life of me, I can't seem to get that to
work. I have contacted Apple Support but they have no clue what I am talking
about (meaning getting the laptop to authenticate with AD). They told me to
create another account called the "username" and give local admin rights to
it. That is not what I want. I know how to do that but I want to be able to
set up this laptop where the user is able to log into the network and if she
decide to take the laptop home to work that she will be able to log in
locally.

Hi Helen!

I think I understand your problem and everything you're doing sounds
fine. If your user's problem is that she can log in quickly while
connected to the network but off the network the login takes a long time
then the issue is that your Mac is trying to connect to a domain
controller that isn't available. It's a documented bug.

I've found that while connected to your company network (probably via
Ethernet cable) be sure that wireless networking is turned off.
Shutdown, move off the network and then she'll probably be able to log
in normally. If necessary, enable wireless networking after logging in.
Basically, make sure that no network connection is active while trying
to log in away from the AD network.

The following is an excerpt from the MacEnterprise mailing list around
mid-November and was posted by Jeremy Reichman:

If this is happening when the computer is in range of a wireless network or
connected to another wired network -- either of which is not your
organization's network -- then it has been discussed on the list this summer
and fall. It might have been easy to miss the threads, even in the archives..

It seems to happen when Active Directory domain controllers are
visible/resolvable (i.e. scutil -r may show them as "Reachable") but not
otherwise responding to traffic.

In those threads and subsequent conversations, a few distinct ideas I recall
came up:

* Remove Active Directory from the Authentication path in Directory
Access, but make sure you are using only Mobile accounts (the accounts must
be cached since you will no longer be communicating with Active Directory)

* Reduce the four timeouts in the ActiveDirectory.plist from 200 to some
smaller number, so that failover to mobile accounts occurs more quickly when
domain controllers are not available

* Split DNS to make your domain controllers not be visible from outside
your own network.

Hope this helps! bill
--
William M. Smith
(Microsoft Interop MVP - Mac/Windows)
.



Relevant Pages

  • Re: ipfw plus authentication (authpf is cool but....)
    ... their ipaddress, mac address, workstation os, etc. in our ldap directory. ... gain network access is indeed belongs to that user. ... router first before being allowed to access any server. ... user will authenticate to a web based login form which is tied up ...
    (freebsd-questions)
  • Re: [opensuse] Results of moving ssh to a high port - Zero scriptkiddies in a 24 hour period.
    ... I would generally prefer the password protected key option (to use the ... key you have to authenticate with a password), ... For gaining access to a specific node in your network, ... It raises the security level drastivally, but at what costs, is it ...
    (SuSE)
  • Re: AD Security Groups break Authentication
    ... users no longer seem to authenticate to the ... If I try and map a network drive, ... Please reply back to the newsgroup or forum for collaboration benefit among responding engineers, and to help others benefit from your resolution. ... Microsoft MVP - Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: Authenticating users through firewalls VPN
    ... Grab DrTCP and try reducing the MTU size. ... VPN to my internal network. ... it won't authenticate me so will not let me, for example, browse the ...
    (microsoft.public.windows.server.sbs)
  • Re: Sites - Public / Global adress.
    ... The domain members and the domain controllers need to be on ... this normally would be a "private" network address. ... > they are not sure what site they are in and try and authenticate from ...
    (microsoft.public.windows.server.networking)